Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,624 matching · page 1368/1453Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2021-46813(opens NVD record) | High | 7.5 | Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability. | Jun 13, 2022 |
| CVE-2021-46812(opens NVD record) | High | 7.5 | The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity. | Jun 13, 2022 |
| CVE-2021-46811(opens NVD record) | Medium | 5.3 | HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information. | Jun 13, 2022 |
| CVE-2022-31763(opens NVD record) | Medium | 5.5 | The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-31762(opens NVD record) | High | 7.8 | The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation. | Jun 13, 2022 |
| CVE-2022-31759(opens NVD record) | Medium | 5.5 | AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-31758(opens NVD record) | Medium | 4.7 | The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Jun 13, 2022 |
| CVE-2022-31756(opens NVD record) | Medium | 5.5 | The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality. | Jun 13, 2022 |
| CVE-2022-31755(opens NVD record) | Medium | 5.5 | The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-31751(opens NVD record) | Medium | 5.5 | The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2021-46814(opens NVD record) | High | 7.5 | The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability. | Jun 13, 2022 |
| CVE-2022-29244(opens NVD record) | High | 7.5 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm. | Jun 13, 2022 |
| CVE-2021-46818(opens NVD record) | High | 7.8 | Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file. | Jun 13, 2022 |
| CVE-2021-46817(opens NVD record) | High | 7.8 | Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file. | Jun 13, 2022 |
| CVE-2021-46816(opens NVD record) | High | 7.8 | Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious M4A file. | Jun 13, 2022 |
| CVE-2022-2013(opens NVD record) | High | 7.5 | In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space. | Jun 13, 2022 |
| CVE-2022-32981(opens NVD record) | High | 7.8 | An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers. | Jun 10, 2022 |
| CVE-2022-29095(opens NVD record) | High | 8.3 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system. | Jun 10, 2022 |
| CVE-2022-29094(opens NVD record) | High | 7.1 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | Jun 10, 2022 |
| CVE-2022-29093(opens NVD record) | High | 7.1 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | Jun 10, 2022 |
| CVE-2022-29092(opens NVD record) | High | 7.8 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | Jun 10, 2022 |
| CVE-2022-25845(opens NVD record) | High | 8.1 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode). | Jun 10, 2022 |
| CVE-2022-31769(opens NVD record) | Medium | 5.3 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219. | Jun 10, 2022 |
| CVE-2022-30611(opens NVD record) | Medium | 5.4 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 227364. | Jun 10, 2022 |
| CVE-2022-30610(opens NVD record) | Medium | 4.5 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 227363. | Jun 10, 2022 |
| CVE-2022-22479(opens NVD record) | High | 8.8 | IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. | Jun 10, 2022 |
| CVE-2022-22426(opens NVD record) | Low | 3.3 | IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain unauthorized access to the Spectrum Copy Data Management catalog which contains metadata. IBM X-Force ID: 223718. | Jun 10, 2022 |
| CVE-2022-27502(opens NVD record) | High | 7.8 | RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. | Jun 10, 2022 |
| CVE-2022-30703(opens NVD record) | High | 7.8 | Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information. This vulnerability could also potentially be chained for privilege escalation. | Jun 9, 2022 |
| CVE-2022-30702(opens NVD record) | Medium | 5.5 | Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that could allow an attacker to disclose sensitive information on an affected machine. | Jun 9, 2022 |
| CVE-2022-21499(opens NVD record) | Medium | 6.7 | KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). | Jun 9, 2022 |
| CVE-2022-31813(opens NVD record) | Critical | 9.8 | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application. | Jun 9, 2022 |
| CVE-2022-30556(opens NVD record) | High | 7.5 | Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. | Jun 9, 2022 |
| CVE-2022-30522(opens NVD record) | High | 7.5 | If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. | Jun 9, 2022 |
| CVE-2022-29404(opens NVD record) | High | 7.5 | In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. | Jun 9, 2022 |
| CVE-2022-28615(opens NVD record) | Critical | 9.1 | Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected. | Jun 9, 2022 |
| CVE-2022-28614(opens NVD record) | Medium | 5.3 | The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue. | Jun 9, 2022 |
| CVE-2022-28330(opens NVD record) | Medium | 5.3 | Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module. | Jun 9, 2022 |
| CVE-2022-26377(opens NVD record) | High | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions. | Jun 9, 2022 |
| CVE-2022-1992(opens NVD record) | Critical | 9.1 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | Jun 9, 2022 |
| CVE-2022-1998(opens NVD record) | High | 7.8 | A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system. | Jun 9, 2022 |
| CVE-2022-30075(opens NVD record) | High | 8.8 | In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation. | Jun 9, 2022 |
| CVE-2022-1703(opens NVD record) | High | 8.8 | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack. | Jun 8, 2022 |
| CVE-2022-1708(opens NVD record) | High | 7.5 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus, if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability. | Jun 7, 2022 |
| CVE-2020-36531(opens NVD record) | Medium | 6.3 | A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely. | Jun 7, 2022 |
| CVE-2020-36530(opens NVD record) | Medium | 6.3 | A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely. | Jun 7, 2022 |
| CVE-2020-36529(opens NVD record) | High | 8.8 | A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation with a command injection. It is possible to initiate the attack remotely. | Jun 7, 2022 |
| CVE-2022-25361(opens NVD record) | Critical | 9.1 | WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | Jun 7, 2022 |
| CVE-2022-27438(opens NVD record) | High | 8.1 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check. | Jun 6, 2022 |
| CVE-2022-31768(opens NVD record) | Critical | 9.8 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | Jun 6, 2022 |