Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,155 matching · page 1349/1444Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-31097(opens NVD record) | High | 7.3 | Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting. | Jul 15, 2022 |
| CVE-2022-23825(opens NVD record) | Medium | 6.5 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | Jul 14, 2022 |
| CVE-2022-22460(opens NVD record) | High | 7.5 | IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013. | Jul 14, 2022 |
| CVE-2022-22453(opens NVD record) | High | 7.5 | IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. | Jul 14, 2022 |
| CVE-2022-22452(opens NVD record) | High | 7.5 | IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918. | Jul 14, 2022 |
| CVE-2022-22450(opens NVD record) | Low | 3.8 | IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. | Jul 14, 2022 |
| CVE-2022-35283(opens NVD record) | Medium | 6.5 | IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request. | Jul 14, 2022 |
| CVE-2022-22477(opens NVD record) | Medium | 6.1 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605. | Jul 14, 2022 |
| CVE-2022-22473(opens NVD record) | Medium | 5.3 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force ID: 225347. | Jul 14, 2022 |
| CVE-2021-39028(opens NVD record) | Medium | 5.4 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 213866. | Jul 14, 2022 |
| CVE-2021-39019(opens NVD record) | Medium | 6.5 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728. | Jul 14, 2022 |
| CVE-2021-39018(opens NVD record) | Medium | 4.3 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726. | Jul 14, 2022 |
| CVE-2021-39017(opens NVD record) | Medium | 6.5 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725. | Jul 14, 2022 |
| CVE-2021-39016(opens NVD record) | Medium | 4.3 | IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the software to transmit more traffic than should be allowed for that actor. IBM X-Force ID: 213722. | Jul 14, 2022 |
| CVE-2021-39015(opens NVD record) | Medium | 5.4 | IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213655. | Jul 14, 2022 |
| CVE-2022-32223(opens NVD record) | High | 7.3 | Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability. | Jul 14, 2022 |
| CVE-2022-32215(opens NVD record) | Medium | 6.5 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). | Jul 14, 2022 |
| CVE-2022-32214(opens NVD record) | Medium | 6.5 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). | Jul 14, 2022 |
| CVE-2022-32213(opens NVD record) | Medium | 6.5 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | Jul 14, 2022 |
| CVE-2022-2393(opens NVD record) | Medium | 5.7 | A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content. | Jul 14, 2022 |
| CVE-2022-28876(opens NVD record) | Medium | 4.3 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aeheur.dll component can crash the scanning engine. The exploit can be triggered remotely by an attacker. | Jul 14, 2022 |
| CVE-2022-30024(opens NVD record) | High | 8.8 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected. | Jul 14, 2022 |
| CVE-2022-22982(opens NVD record) | High | 7.5 | The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. | Jul 13, 2022 |
| CVE-2022-34358(opens NVD record) | Medium | 5.4 | IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516. | Jul 13, 2022 |
| CVE-2022-32074(opens NVD record) | Medium | 5.4 | A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file. | Jul 13, 2022 |
| CVE-2022-33678(opens NVD record) | High | 7.2 | Azure Site Recovery Remote Code Execution Vulnerability | Jul 12, 2022 |
| CVE-2022-33677(opens NVD record) | High | 7.2 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33676(opens NVD record) | High | 7.2 | Azure Site Recovery Remote Code Execution Vulnerability | Jul 12, 2022 |
| CVE-2022-33675(opens NVD record) | High | 7.8 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33674(opens NVD record) | High | 8.3 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33673(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33672(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33671(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33669(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33668(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33667(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33666(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33665(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33664(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33663(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33662(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33661(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33660(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33659(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33658(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33657(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33656(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33655(opens NVD record) | Medium | 6.5 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33654(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |
| CVE-2022-33653(opens NVD record) | Medium | 4.9 | Azure Site Recovery Elevation of Privilege Vulnerability | Jul 12, 2022 |