Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,155 matching · page 1358/1444Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2021-39820(opens NVD record) | High | 7.8 | Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | Jun 15, 2022 |
| CVE-2022-22444(opens NVD record) | Medium | 5.5 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a denial of service. IBM X-Force ID: 224444. | Jun 15, 2022 |
| CVE-2021-41672(opens NVD record) | Medium | 6.5 | PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database. | Jun 15, 2022 |
| CVE-2019-4575(opens NVD record) | Critical | 9.8 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 166801. | Jun 15, 2022 |
| CVE-2022-32230(opens NVD record) | High | 7.5 | Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the Windows kernel. For most systems, this attack requires authentication, except in the special case of Windows Domain Controllers, where unauthenticated users can always open named pipes as long as they can establish an SMB session. Typically, after the BSOD, the victim SMBv3 server will reboot. | Jun 14, 2022 |
| CVE-2022-30903(opens NVD record) | Medium | 4.8 | Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management. | Jun 14, 2022 |
| CVE-2022-21504(opens NVD record) | Medium | 5.5 | The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in a use count error that allowed a file descriptor to a socket to be closed and freed while it was still in use by another portion of the kernel. An attack with local access can operate on the socket, and cause a denial of service. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). | Jun 14, 2022 |
| CVE-2021-42675(opens NVD record) | Critical | 9.8 | Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution. | Jun 14, 2022 |
| CVE-2021-40650(opens NVD record) | Medium | 6.5 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set. | Jun 14, 2022 |
| CVE-2021-40649(opens NVD record) | Medium | 6.5 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set. | Jun 14, 2022 |
| CVE-2022-29798(opens NVD record) | High | 7.5 | There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation could cause denial of service. | Jun 13, 2022 |
| CVE-2022-29797(opens NVD record) | Critical | 9.8 | There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation. | Jun 13, 2022 |
| CVE-2022-22259(opens NVD record) | Medium | 6.8 | There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device. | Jun 13, 2022 |
| CVE-2021-41663(opens NVD record) | Medium | 6.1 | A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page. | Jun 13, 2022 |
| CVE-2021-40036(opens NVD record) | Critical | 9.8 | The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution. | Jun 13, 2022 |
| CVE-2022-31761(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality. | Jun 13, 2022 |
| CVE-2022-31760(opens NVD record) | Critical | 9.1 | Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality. | Jun 13, 2022 |
| CVE-2022-31757(opens NVD record) | High | 7.5 | The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect data confidentiality. | Jun 13, 2022 |
| CVE-2022-31754(opens NVD record) | High | 7.5 | Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the availability of some features. | Jun 13, 2022 |
| CVE-2022-31753(opens NVD record) | High | 7.5 | The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-31752(opens NVD record) | Medium | 5.5 | Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality. | Jun 13, 2022 |
| CVE-2021-46813(opens NVD record) | High | 7.5 | Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability. | Jun 13, 2022 |
| CVE-2021-46812(opens NVD record) | High | 7.5 | The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity. | Jun 13, 2022 |
| CVE-2021-46811(opens NVD record) | Medium | 5.3 | HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information. | Jun 13, 2022 |
| CVE-2022-31763(opens NVD record) | Medium | 5.5 | The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-31762(opens NVD record) | High | 7.8 | The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation. | Jun 13, 2022 |
| CVE-2022-31759(opens NVD record) | Medium | 5.5 | AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-31758(opens NVD record) | Medium | 4.7 | The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Jun 13, 2022 |
| CVE-2022-31756(opens NVD record) | Medium | 5.5 | The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality. | Jun 13, 2022 |
| CVE-2022-31755(opens NVD record) | Medium | 5.5 | The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-31751(opens NVD record) | Medium | 5.5 | The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2021-46814(opens NVD record) | High | 7.5 | The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-29244(opens NVD record) | High | 7.5 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm. | Jun 13, 2022 |
| CVE-2021-46818(opens NVD record) | High | 7.8 | Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file. | Jun 13, 2022 |
| CVE-2021-46817(opens NVD record) | High | 7.8 | Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file. | Jun 13, 2022 |
| CVE-2021-46816(opens NVD record) | High | 7.8 | Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file. | Jun 13, 2022 |
| CVE-2022-2013(opens NVD record) | High | 7.5 | In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space. | Jun 13, 2022 |
| CVE-2022-32981(opens NVD record) | High | 7.8 | An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers. | Jun 10, 2022 |
| CVE-2022-29095(opens NVD record) | High | 8.3 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system. | Jun 10, 2022 |
| CVE-2022-29094(opens NVD record) | High | 7.1 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | Jun 10, 2022 |
| CVE-2022-29093(opens NVD record) | High | 7.1 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | Jun 10, 2022 |
| CVE-2022-29092(opens NVD record) | High | 7.8 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | Jun 10, 2022 |
| CVE-2022-25845(opens NVD record) | High | 8.1 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode). | Jun 10, 2022 |
| CVE-2022-31769(opens NVD record) | Medium | 5.3 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219. | Jun 10, 2022 |
| CVE-2022-30611(opens NVD record) | Medium | 5.4 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 227364. | Jun 10, 2022 |
| CVE-2022-30610(opens NVD record) | Medium | 4.5 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 227363. | Jun 10, 2022 |
| CVE-2022-22479(opens NVD record) | High | 8.8 | IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. | Jun 10, 2022 |
| CVE-2022-22426(opens NVD record) | Low | 3.3 | IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain unauthorized access to the Spectrum Copy Data Management catalog which contains metadata. IBM X-Force ID: 223718. | Jun 10, 2022 |
| CVE-2022-27502(opens NVD record) | High | 7.8 | RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. | Jun 10, 2022 |
| CVE-2022-30703(opens NVD record) | High | 7.8 | Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information. This vulnerability could also potentially be chained for privilege escalation. | Jun 9, 2022 |