Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,155 matching · page 1362/1444Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-30600(opens NVD record) | Critical | 9.8 | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. | May 18, 2022 |
| CVE-2022-30599(opens NVD record) | Critical | 9.8 | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. | May 18, 2022 |
| CVE-2022-30598(opens NVD record) | Medium | 4.3 | A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it. | May 18, 2022 |
| CVE-2022-30597(opens NVD record) | Medium | 5.3 | A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. | May 18, 2022 |
| CVE-2022-30596(opens NVD record) | Medium | 5.4 | A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk. | May 18, 2022 |
| CVE-2022-1734(opens NVD record) | High | 7.0 | A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. | May 18, 2022 |
| CVE-2022-0883(opens NVD record) | High | 7.3 | SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | May 18, 2022 |
| CVE-2022-30065(opens NVD record) | High | 7.8 | A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function. | May 18, 2022 |
| CVE-2022-29641(opens NVD record) | High | 7.5 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | May 18, 2022 |
| CVE-2022-28616(opens NVD record) | Critical | 9.8 | A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | May 17, 2022 |
| CVE-2022-1362(opens NVD record) | Medium | 5.0 | The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the server. | May 17, 2022 |
| CVE-2022-1361(opens NVD record) | High | 7.4 | The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices. | May 17, 2022 |
| CVE-2022-1360(opens NVD record) | High | 8.2 | The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings. | May 17, 2022 |
| CVE-2022-1359(opens NVD record) | Medium | 5.7 | The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server. | May 17, 2022 |
| CVE-2022-1358(opens NVD record) | Medium | 5.9 | The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database. | May 17, 2022 |
| CVE-2022-1357(opens NVD record) | Critical | 9.8 | The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to append arbitrary data to the logger command. | May 17, 2022 |
| CVE-2022-1356(opens NVD record) | High | 7.1 | cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands. | May 17, 2022 |
| CVE-2022-28617(opens NVD record) | Critical | 9.8 | A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | May 17, 2022 |
| CVE-2022-28192(opens NVD record) | Medium | 4.1 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges. | May 17, 2022 |
| CVE-2022-28191(opens NVD record) | Medium | 5.5 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service. | May 17, 2022 |
| CVE-2022-28190(opens NVD record) | Medium | 5.5 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper input validation can cause denial of service. | May 17, 2022 |
| CVE-2022-28189(opens NVD record) | Medium | 5.5 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a NULL pointer dereference may lead to a system crash. | May 17, 2022 |
| CVE-2022-28188(opens NVD record) | Medium | 5.5 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service. | May 17, 2022 |
| CVE-2022-28187(opens NVD record) | Medium | 5.5 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where the memory management software does not release a resource after its effective lifetime has ended, which may lead to denial of service. | May 17, 2022 |
| CVE-2022-28186(opens NVD record) | Medium | 6.1 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service or data tampering. | May 17, 2022 |
| CVE-2022-28185(opens NVD record) | Medium | 6.8 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering. | May 17, 2022 |
| CVE-2022-28184(opens NVD record) | High | 7.1 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering. | May 17, 2022 |
| CVE-2022-28183(opens NVD record) | High | 7.7 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause an out-of-bounds read, which may lead to denial of service and information disclosure. | May 17, 2022 |
| CVE-2022-28182(opens NVD record) | High | 8.5 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components. | May 17, 2022 |
| CVE-2022-28181(opens NVD record) | High | 8.5 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components. | May 17, 2022 |
| CVE-2022-23706(opens NVD record) | Medium | 6.1 | A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | May 17, 2022 |
| CVE-2021-35249(opens NVD record) | Medium | 4.3 | This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a data leak to unauthorized users for a domain, with no log of them accessing the data unless they attempt to modify it. This read-only activity is logged to the original domain and does not specify which domain was accessed. | May 17, 2022 |
| CVE-2022-23674(opens NVD record) | Medium | 5.4 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 17, 2022 |
| CVE-2022-24611(opens NVD record) | Medium | 6.5 | Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs. | May 17, 2022 |
| CVE-2022-23675(opens NVD record) | Medium | 4.8 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 17, 2022 |
| CVE-2022-23673(opens NVD record) | High | 7.2 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 17, 2022 |
| CVE-2022-23672(opens NVD record) | High | 7.2 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 17, 2022 |
| CVE-2022-23671(opens NVD record) | High | 7.5 | A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 17, 2022 |
| CVE-2022-23669(opens NVD record) | High | 8.8 | A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 17, 2022 |
| CVE-2022-1706(opens NVD record) | Medium | 6.5 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config. | May 17, 2022 |
| CVE-2022-29581(opens NVD record) | High | 7.8 | Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions. | May 17, 2022 |
| CVE-2022-22482(opens NVD record) | Medium | 6.5 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files that could fill up the filesystem and cause a denial of service. IBM X-Force ID: 225977. | May 17, 2022 |
| CVE-2022-22475(opens NVD record) | Medium | 6.5 | IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603. | May 17, 2022 |
| CVE-2022-1116(opens NVD record) | High | 7.8 | Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions. | May 17, 2022 |
| CVE-2021-38872(opens NVD record) | High | 7.5 | IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force ID: 208348. | May 17, 2022 |
| CVE-2021-29726(opens NVD record) | Medium | 5.3 | IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104. | May 17, 2022 |
| CVE-2020-4994(opens NVD record) | High | 7.5 | IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906. | May 17, 2022 |
| CVE-2022-22484(opens NVD record) | Medium | 5.5 | IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser history, an attacker could exploit this vulnerability to obtain other user accounts' passwords. IBM X-Force ID: 226322. | May 17, 2022 |
| CVE-2020-4957(opens NVD record) | Medium | 5.3 | IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks against the system. IBM X-Force ID: 192208. | May 17, 2022 |
| CVE-2022-23670(opens NVD record) | Medium | 6.5 | A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |