Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,145 matching · page 1363/1443Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-23668(opens NVD record) | Medium | 4.9 | A remote authenticated server-side request forgery (ssrf) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manage that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23667(opens NVD record) | High | 7.2 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-1587(opens NVD record) | Critical | 9.1 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers. | May 16, 2022 |
| CVE-2022-1586(opens NVD record) | Critical | 9.1 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT. | May 16, 2022 |
| CVE-2022-23666(opens NVD record) | Critical | 9.1 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23665(opens NVD record) | Critical | 9.1 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23664(opens NVD record) | Critical | 9.1 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23663(opens NVD record) | Critical | 9.1 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23662(opens NVD record) | Critical | 9.1 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23661(opens NVD record) | Critical | 9.1 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23660(opens NVD record) | Critical | 10.0 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23659(opens NVD record) | Medium | 6.1 | A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23658(opens NVD record) | Critical | 10.0 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-23657(opens NVD record) | Critical | 10.0 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | May 16, 2022 |
| CVE-2022-1679(opens NVD record) | High | 7.8 | A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system. | May 16, 2022 |
| CVE-2022-30126(opens NVD record) | Medium | 5.5 | In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0 | May 16, 2022 |
| CVE-2022-30055(opens NVD record) | Critical | 9.8 | Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. | May 16, 2022 |
| CVE-2022-25169(opens NVD record) | Medium | 5.5 | The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. | May 16, 2022 |
| CVE-2022-30523(opens NVD record) | High | 7.8 | Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege escalation on the affected machine. | May 16, 2022 |
| CVE-2022-29351(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here. | May 16, 2022 |
| CVE-2022-25865(opens NVD record) | High | 8.1 | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. | May 13, 2022 |
| CVE-2022-22282(opens NVD record) | Critical | 9.8 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability. | May 13, 2022 |
| CVE-2022-22281(opens NVD record) | High | 7.8 | A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system. | May 13, 2022 |
| CVE-2022-1702(opens NVD record) | Medium | 6.1 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability. | May 13, 2022 |
| CVE-2022-1701(opens NVD record) | High | 7.5 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data. | May 13, 2022 |
| CVE-2022-22393(opens NVD record) | Medium | 6.5 | IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078. | May 13, 2022 |
| CVE-2022-22325(opens NVD record) | Medium | 5.5 | IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853. | May 13, 2022 |
| CVE-2022-22252(opens NVD record) | High | 7.5 | The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability. | May 13, 2022 |
| CVE-2022-29796(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-29795(opens NVD record) | High | 7.5 | The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability. | May 13, 2022 |
| CVE-2022-29794(opens NVD record) | Critical | 9.8 | The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality. | May 13, 2022 |
| CVE-2022-29793(opens NVD record) | High | 7.5 | There is a configuration defect in the activation lock of mobile phones.Successful exploitation of this vulnerability may affect application availability. | May 13, 2022 |
| CVE-2022-29792(opens NVD record) | High | 7.5 | The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality. | May 13, 2022 |
| CVE-2022-29791(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-29790(opens NVD record) | High | 7.5 | The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions. | May 13, 2022 |
| CVE-2022-29789(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-28830(opens NVD record) | Medium | 5.5 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28829(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28828(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28827(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28826(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28825(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28824(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28823(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28822(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28821(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-22261(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-22260(opens NVD record) | Critical | 9.1 | The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability. | May 13, 2022 |
| CVE-2021-46789(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability. | May 13, 2022 |
| CVE-2021-46788(opens NVD record) | High | 7.5 | Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations. | May 13, 2022 |