Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,624 matching · page 1369/1453Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-22396(opens NVD record) | High | 7.5 | Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key or certificate are not printed. IBM X-Force ID: 222231. | Jun 6, 2022 |
| CVE-2022-29594(opens NVD record) | High | 7.8 | eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. | Jun 2, 2022 |
| CVE-2022-32250(opens NVD record) | High | 7.8 | net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. | Jun 2, 2022 |
| CVE-2022-29085(opens NVD record) | Medium | 6.4 | Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user. | Jun 2, 2022 |
| CVE-2022-29084(opens NVD record) | High | 8.1 | Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users. | Jun 2, 2022 |
| CVE-2022-26869(opens NVD record) | Critical | 9.8 | Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution. | Jun 2, 2022 |
| CVE-2022-26868(opens NVD record) | Medium | 6.4 | Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover by an attacker. | Jun 2, 2022 |
| CVE-2022-26867(opens NVD record) | Medium | 5.9 | PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file. | Jun 2, 2022 |
| CVE-2022-26866(opens NVD record) | Medium | 5.5 | Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery. | Jun 2, 2022 |
| CVE-2022-22557(opens NVD record) | High | 7.5 | PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. | Jun 2, 2022 |
| CVE-2022-22556(opens NVD record) | Low | 3.7 | Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service. | Jun 2, 2022 |
| CVE-2021-42877(opens NVD record) | High | 7.5 | TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system. | Jun 2, 2022 |
| CVE-2021-42875(opens NVD record) | Critical | 9.8 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin. | Jun 2, 2022 |
| CVE-2022-29704(opens NVD record) | Critical | 9.8 | BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability. | Jun 2, 2022 |
| CVE-2021-45983(opens NVD record) | Critical | 9.8 | NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution. | Jun 2, 2022 |
| CVE-2021-45982(opens NVD record) | High | 8.8 | NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. | Jun 2, 2022 |
| CVE-2021-45981(opens NVD record) | Critical | 9.8 | NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. | Jun 2, 2022 |
| CVE-2022-30490(opens NVD record) | Critical | 9.8 | Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php. | Jun 2, 2022 |
| CVE-2022-30115(opens NVD record) | Medium | 4.3 | Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL. | Jun 2, 2022 |
| CVE-2022-30034(opens NVD record) | High | 8.6 | Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes. | Jun 2, 2022 |
| CVE-2022-28945(opens NVD record) | Critical | 9.8 | An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file. | Jun 2, 2022 |
| CVE-2022-27781(opens NVD record) | High | 7.5 | libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation. | Jun 2, 2022 |
| CVE-2022-27780(opens NVD record) | High | 7.5 | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0.0.1/`, would be allowed bythe parser and get transposed into `http://example.com/127.0.0.1/`. This flawcan be used to circumvent filters, checks and more. | Jun 2, 2022 |
| CVE-2022-27779(opens NVD record) | Medium | 5.3 | libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided, a more rudimentary check exists to atleast prevent cookies from being set on TLDs. This check was broken if thehost name in the URL uses a trailing dot.This can allow arbitrary sites to set cookies that then would get sent to adifferent and unrelated site or domain. | Jun 2, 2022 |
| CVE-2022-27778(opens NVD record) | High | 8.1 | A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. | Jun 2, 2022 |
| CVE-2022-27776(opens NVD record) | Medium | 6.5 | A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. | Jun 2, 2022 |
| CVE-2022-27775(opens NVD record) | High | 7.5 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. | Jun 2, 2022 |
| CVE-2022-27774(opens NVD record) | Medium | 5.7 | An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers. | Jun 2, 2022 |
| CVE-2022-24581(opens NVD record) | High | 7.5 | ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software. | Jun 2, 2022 |
| CVE-2022-24241(opens NVD record) | High | 7.5 | ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp. | Jun 2, 2022 |
| CVE-2022-24240(opens NVD record) | Critical | 9.8 | ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp. | Jun 2, 2022 |
| CVE-2022-24239(opens NVD record) | Critical | 9.8 | ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp. | Jun 2, 2022 |
| CVE-2022-24238(opens NVD record) | Medium | 6.1 | ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp. | Jun 2, 2022 |
| CVE-2022-23237(opens NVD record) | Medium | 6.1 | E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites. | Jun 2, 2022 |
| CVE-2022-23236(opens NVD record) | Medium | 4.4 | E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users. | Jun 2, 2022 |
| CVE-2022-1949(opens NVD record) | High | 7.5 | An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data. | Jun 2, 2022 |
| CVE-2022-1789(opens NVD record) | Medium | 6.8 | With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference. | Jun 2, 2022 |
| CVE-2022-1786(opens NVD record) | High | 7.8 | A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system. | Jun 2, 2022 |
| CVE-2022-1652(opens NVD record) | High | 7.8 | Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system. | Jun 2, 2022 |
| CVE-2022-1462(opens NVD record) | Medium | 6.3 | An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition using ioctls TIOCSPTLCK and TIOCGPTPEER and TIOCSTI and TCXONC with leakage of memory in the flush_to_ldisc function. This flaw allows a local user to crash the system or read unauthorized random data from memory. | Jun 2, 2022 |
| CVE-2021-42872(opens NVD record) | Critical | 9.8 | TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code. | Jun 2, 2022 |
| CVE-2021-33615(opens NVD record) | High | 7.5 | RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type. | Jun 2, 2022 |
| CVE-2022-30190(opens NVD record) | High | 7.8 | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability. | Jun 1, 2022 |
| CVE-2022-30128(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Jun 1, 2022 |
| CVE-2022-30127(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Jun 1, 2022 |
| CVE-2022-26905(opens NVD record) | Medium | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Jun 1, 2022 |
| CVE-2022-29098(opens NVD record) | High | 8.1 | Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise. | Jun 1, 2022 |
| CVE-2020-26185(opens NVD record) | High | 7.5 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. | Jun 1, 2022 |
| CVE-2020-26184(opens NVD record) | High | 7.5 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability. | Jun 1, 2022 |
| CVE-2022-22361(opens NVD record) | Medium | 6.5 | IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0 through 8.6.0.201803, and 8.5.0.0 through 8.5.0.201706 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | May 31, 2022 |