Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,857 matching · page 1333/1438Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-33927(opens NVD record) | Medium | 5.4 | Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session. | Aug 10, 2022 |
| CVE-2022-33926(opens NVD record) | High | 7.1 | Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked. | Aug 10, 2022 |
| CVE-2022-33925(opens NVD record) | Medium | 6.5 | Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information. | Aug 10, 2022 |
| CVE-2022-33924(opens NVD record) | Medium | 4.3 | Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access to create rules could potentially exploit this vulnerability and create rules. | Aug 10, 2022 |
| CVE-2022-29090(opens NVD record) | High | 8.5 | Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target device and perform unauthorized actions. | Aug 10, 2022 |
| CVE-2022-22490(opens NVD record) | Medium | 4.9 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. | Aug 10, 2022 |
| CVE-2022-22411(opens NVD record) | Medium | 6.5 | IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016. | Aug 10, 2022 |
| CVE-2022-22369(opens NVD record) | High | 7.1 | IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system to crash. IBM X-Force ID: 221187. | Aug 10, 2022 |
| CVE-2022-20866(opens NVD record) | High | 7.4 | A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability is due to a logic error when the RSA key is stored in memory on a hardware platform that performs hardware-based cryptography. An attacker could exploit this vulnerability by using a Lenstra side-channel attack against the targeted device. A successful exploit could allow the attacker to retrieve the RSA private key. The following conditions may be observed on an affected device: This vulnerability will apply to approximately 5 percent of the RSA keys on a device that is running a vulnerable release of Cisco ASA Software or Cisco FTD Software; not all RSA keys are expected to be affected due to mathematical calculations applied to the RSA key. The RSA key could be valid but have specific characteristics that make it vulnerable to the potential leak of the RSA private key. If an attacker obtains the RSA private key, they could use the key to impersonate a device that is running Cisco ASA Software or Cisco FTD Software or to decrypt the device traffic. See the Indicators of Compromise section for more information on the detection of this type of RSA key. The RSA key could be malformed and invalid. A malformed RSA key is not functional, and a TLS client connection to a device that is running Cisco ASA Software or Cisco FTD Software that uses the malformed RSA key will result in a TLS signature failure, which means a vulnerable software release created an invalid RSA signature that failed verification. If an attacker obtains the RSA private key, they could use the key to impersonate a device that is running Cisco ASA Software or Cisco FTD Software or to decrypt the device traffic. | Aug 10, 2022 |
| CVE-2022-20713(opens NVD record) | Medium | 4.3 | A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of input that is passed to the VPN web client services component before being returned to the browser that is in use. An attacker could exploit this vulnerability by persuading a user to visit a website that is designed to pass malicious requests to a device that is running Cisco ASA Software or Cisco FTD Software and has web services endpoints supporting VPN features enabled. A successful exploit could allow the attacker to reflect malicious input from the affected device to the browser that is in use and conduct browser-based attacks, including cross-site scripting attacks. The attacker could not directly impact the affected device. | Aug 10, 2022 |
| CVE-2022-0028(opens NVD record) | High | 8.6 | A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them. | Aug 10, 2022 |
| CVE-2022-34659(opens NVD record) | Medium | 5.3 | A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public license server is used. This could allow an attacker to retrieve this information. | Aug 10, 2022 |
| CVE-2022-20914(opens NVD record) | Medium | 4.9 | A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server. Note: To successfully exploit this vulnerability, the attacker must have valid ERS administrative credentials. | Aug 10, 2022 |
| CVE-2022-20869(opens NVD record) | Medium | 6.1 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. | Aug 10, 2022 |
| CVE-2022-20852(opens NVD record) | Medium | 5.4 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities, see the Details section of this advisory. | Aug 10, 2022 |
| CVE-2022-20842(opens NVD record) | Critical | 9.0 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | Aug 10, 2022 |
| CVE-2022-20827(opens NVD record) | Critical | 9.0 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | Aug 10, 2022 |
| CVE-2022-20820(opens NVD record) | Medium | 5.4 | Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities, see the Details section of this advisory. | Aug 10, 2022 |
| CVE-2022-20816(opens NVD record) | Medium | 6.5 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary files from an affected system. This vulnerability exists because the affected software does not properly validate HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system. | Aug 10, 2022 |
| CVE-2022-20841(opens NVD record) | Critical | 9.0 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | Aug 10, 2022 |
| CVE-2022-29083(opens NVD record) | Medium | 6.8 | Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system. | Aug 9, 2022 |
| CVE-2022-35827(opens NVD record) | High | 8.8 | Visual Studio Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-35826(opens NVD record) | High | 8.8 | Visual Studio Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-35825(opens NVD record) | High | 8.8 | Visual Studio Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-35824(opens NVD record) | High | 7.2 | Azure Site Recovery Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-35821(opens NVD record) | Medium | 4.4 | Azure Sphere Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-35820(opens NVD record) | High | 7.8 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35819(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35818(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35817(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35816(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35815(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35814(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35813(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35812(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35811(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35810(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35809(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35808(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35807(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35806(opens NVD record) | High | 7.8 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-35804(opens NVD record) | High | 8.8 | SMB Client and Server Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-35802(opens NVD record) | High | 8.1 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35801(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35800(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35799(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35797(opens NVD record) | Medium | 6.1 | Windows Hello Security Feature Bypass Vulnerability | Aug 9, 2022 |
| CVE-2022-35796(opens NVD record) | High | 7.5 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35795(opens NVD record) | High | 7.8 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-35794(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Aug 9, 2022 |