Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,155 matching · page 1359/1444Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-30702(opens NVD record) | Medium | 5.5 | Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that could allow an attacker to disclose sensitive information on an affected machine. | Jun 9, 2022 |
| CVE-2022-21499(opens NVD record) | Medium | 6.7 | KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). | Jun 9, 2022 |
| CVE-2022-31813(opens NVD record) | Critical | 9.8 | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application. | Jun 9, 2022 |
| CVE-2022-30556(opens NVD record) | High | 7.5 | Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. | Jun 9, 2022 |
| CVE-2022-30522(opens NVD record) | High | 7.5 | If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. | Jun 9, 2022 |
| CVE-2022-29404(opens NVD record) | High | 7.5 | In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. | Jun 9, 2022 |
| CVE-2022-28615(opens NVD record) | Critical | 9.1 | Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected. | Jun 9, 2022 |
| CVE-2022-28614(opens NVD record) | Medium | 5.3 | The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue. | Jun 9, 2022 |
| CVE-2022-28330(opens NVD record) | Medium | 5.3 | Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module. | Jun 9, 2022 |
| CVE-2022-26377(opens NVD record) | High | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions. | Jun 9, 2022 |
| CVE-2022-1992(opens NVD record) | Critical | 9.1 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | Jun 9, 2022 |
| CVE-2022-1998(opens NVD record) | High | 7.8 | A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system. | Jun 9, 2022 |
| CVE-2022-30075(opens NVD record) | High | 8.8 | In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation. | Jun 9, 2022 |
| CVE-2022-1703(opens NVD record) | High | 8.8 | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack. | Jun 8, 2022 |
| CVE-2022-1708(opens NVD record) | High | 7.5 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus, if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability. | Jun 7, 2022 |
| CVE-2020-36531(opens NVD record) | Medium | 6.3 | A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely. | Jun 7, 2022 |
| CVE-2020-36530(opens NVD record) | Medium | 6.3 | A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely. | Jun 7, 2022 |
| CVE-2020-36529(opens NVD record) | High | 8.8 | A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation with a command injection. It is possible to initiate the attack remotely. | Jun 7, 2022 |
| CVE-2022-25361(opens NVD record) | Critical | 9.1 | WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | Jun 7, 2022 |
| CVE-2022-27438(opens NVD record) | High | 8.1 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check. | Jun 6, 2022 |
| CVE-2022-31768(opens NVD record) | Critical | 9.8 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | Jun 6, 2022 |
| CVE-2022-22396(opens NVD record) | High | 7.5 | Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key or certificate are not printed. IBM X-Force ID: 222231. | Jun 6, 2022 |
| CVE-2022-29594(opens NVD record) | High | 7.8 | eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. | Jun 2, 2022 |
| CVE-2022-32250(opens NVD record) | High | 7.8 | net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. | Jun 2, 2022 |
| CVE-2022-29085(opens NVD record) | Medium | 6.4 | Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user. | Jun 2, 2022 |
| CVE-2022-29084(opens NVD record) | High | 8.1 | Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users. | Jun 2, 2022 |
| CVE-2022-26869(opens NVD record) | Critical | 9.8 | Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution. | Jun 2, 2022 |
| CVE-2022-26868(opens NVD record) | Medium | 6.4 | Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover by an attacker. | Jun 2, 2022 |
| CVE-2022-26867(opens NVD record) | Medium | 5.9 | PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file. | Jun 2, 2022 |
| CVE-2022-26866(opens NVD record) | Medium | 5.5 | Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery. | Jun 2, 2022 |
| CVE-2022-22557(opens NVD record) | High | 7.5 | PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. | Jun 2, 2022 |
| CVE-2022-22556(opens NVD record) | Low | 3.7 | Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service. | Jun 2, 2022 |
| CVE-2021-42877(opens NVD record) | High | 7.5 | TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system. | Jun 2, 2022 |
| CVE-2021-42875(opens NVD record) | Critical | 9.8 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin. | Jun 2, 2022 |
| CVE-2022-29704(opens NVD record) | Critical | 9.8 | BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability. | Jun 2, 2022 |
| CVE-2021-45983(opens NVD record) | Critical | 9.8 | NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution. | Jun 2, 2022 |
| CVE-2021-45982(opens NVD record) | High | 8.8 | NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. | Jun 2, 2022 |
| CVE-2021-45981(opens NVD record) | Critical | 9.8 | NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. | Jun 2, 2022 |
| CVE-2022-30490(opens NVD record) | Critical | 9.8 | Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php. | Jun 2, 2022 |
| CVE-2022-30115(opens NVD record) | Medium | 4.3 | Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL. | Jun 2, 2022 |
| CVE-2022-30034(opens NVD record) | High | 8.6 | Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes. | Jun 2, 2022 |
| CVE-2022-28945(opens NVD record) | Critical | 9.8 | An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file. | Jun 2, 2022 |
| CVE-2022-27781(opens NVD record) | High | 7.5 | libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation. | Jun 2, 2022 |
| CVE-2022-27780(opens NVD record) | High | 7.5 | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more. | Jun 2, 2022 |
| CVE-2022-27779(opens NVD record) | Medium | 5.3 | libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided, a more rudimentary check exists to atleast prevent cookies from being set on TLDs. This check was broken if thehost name in the URL uses a trailing dot.This can allow arbitrary sites to set cookies that then would get sent to adifferent and unrelated site or domain. | Jun 2, 2022 |
| CVE-2022-27778(opens NVD record) | High | 8.1 | A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. | Jun 2, 2022 |
| CVE-2022-27776(opens NVD record) | Medium | 6.5 | A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. | Jun 2, 2022 |
| CVE-2022-27775(opens NVD record) | High | 7.5 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. | Jun 2, 2022 |
| CVE-2022-27774(opens NVD record) | Medium | 5.7 | An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers. | Jun 2, 2022 |
| CVE-2022-24581(opens NVD record) | High | 7.5 | ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software. | Jun 2, 2022 |