Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,624 matching · page 1371/1453Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2020-4926(opens NVD record) | Critical | 9.1 | A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600. | May 24, 2022 |
| CVE-2022-29567(opens NVD record) | Medium | 5.7 | The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side. | May 24, 2022 |
| CVE-2022-22306(opens NVD record) | Medium | 5.4 | An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms. | May 24, 2022 |
| CVE-2022-29376(opens NVD record) | High | 8.8 | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. | May 23, 2022 |
| CVE-2022-28944(opens NVD record) | High | 8.8 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process. | May 23, 2022 |
| CVE-2022-30014(opens NVD record) | High | 8.8 | Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account. | May 23, 2022 |
| CVE-2022-29005(opens NVD record) | Medium | 6.1 | Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters. | May 23, 2022 |
| CVE-2022-29004(opens NVD record) | Medium | 6.1 | Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php. | May 23, 2022 |
| CVE-2022-28932(opens NVD record) | Critical | 9.8 | D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions. | May 23, 2022 |
| CVE-2022-28874(opens NVD record) | Medium | 4.3 | Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker. | May 23, 2022 |
| CVE-2022-22973(opens NVD record) | High | 7.8 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | May 20, 2022 |
| CVE-2022-22972(opens NVD record) | Critical | 9.8 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. | May 20, 2022 |
| CVE-2022-22365(opens NVD record) | Medium | 5.9 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904. | May 20, 2022 |
| CVE-2021-39043(opens NVD record) | Medium | 5.4 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214032. | May 20, 2022 |
| CVE-2022-28987(opens NVD record) | Medium | 5.3 | Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login. | May 20, 2022 |
| CVE-2022-21500(opens NVD record) | High | 7.5 | Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. <br> <br>Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should refer to the Patch Availability Document for details. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | May 20, 2022 |
| CVE-2022-28948(opens NVD record) | High | 7.5 | An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input. | May 19, 2022 |
| CVE-2020-4970(opens NVD record) | Medium | 5.9 | IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 192429. | May 19, 2022 |
| CVE-2022-22978(opens NVD record) | Critical | 9.8 | In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass. | May 19, 2022 |
| CVE-2022-22976(opens NVD record) | Medium | 5.3 | Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE. | May 19, 2022 |
| CVE-2021-26630(opens NVD record) | High | 7.8 | Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function. | May 19, 2022 |
| CVE-2022-1183(opens NVD record) | High | 7.5 | On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch. | May 19, 2022 |
| CVE-2022-30138(opens NVD record) | High | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | May 18, 2022 |
| CVE-2022-30994(opens NVD record) | High | 7.5 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240 | May 18, 2022 |
| CVE-2022-30993(opens NVD record) | High | 7.5 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | May 18, 2022 |
| CVE-2022-30992(opens NVD record) | Medium | 6.1 | Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | May 18, 2022 |
| CVE-2022-30991(opens NVD record) | Medium | 6.1 | HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | May 18, 2022 |
| CVE-2022-30990(opens NVD record) | High | 7.5 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037 | May 18, 2022 |
| CVE-2021-38944(opens NVD record) | Medium | 6.1 | IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 211236. | May 18, 2022 |
| CVE-2022-30600(opens NVD record) | Critical | 9.8 | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. | May 18, 2022 |
| CVE-2022-30599(opens NVD record) | Critical | 9.8 | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. | May 18, 2022 |
| CVE-2022-30598(opens NVD record) | Medium | 4.3 | A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it. | May 18, 2022 |
| CVE-2022-30597(opens NVD record) | Medium | 5.3 | A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. | May 18, 2022 |
| CVE-2022-30596(opens NVD record) | Medium | 5.4 | A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk. | May 18, 2022 |
| CVE-2022-1734(opens NVD record) | High | 7.0 | A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. | May 18, 2022 |
| CVE-2022-0883(opens NVD record) | High | 7.3 | SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | May 18, 2022 |
| CVE-2022-30065(opens NVD record) | High | 7.8 | A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function. | May 18, 2022 |
| CVE-2022-29641(opens NVD record) | High | 7.5 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | May 18, 2022 |
| CVE-2022-28616(opens NVD record) | Critical | 9.8 | A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | May 17, 2022 |
| CVE-2022-1362(opens NVD record) | Medium | 5.0 | The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the server. | May 17, 2022 |
| CVE-2022-1361(opens NVD record) | High | 7.4 | The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices. | May 17, 2022 |
| CVE-2022-1360(opens NVD record) | High | 8.2 | The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings. | May 17, 2022 |
| CVE-2022-1359(opens NVD record) | Medium | 5.7 | The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server. | May 17, 2022 |
| CVE-2022-1358(opens NVD record) | Medium | 5.9 | The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database. | May 17, 2022 |
| CVE-2022-1357(opens NVD record) | Critical | 9.8 | The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to append arbitrary data to the logger command. | May 17, 2022 |
| CVE-2022-1356(opens NVD record) | High | 7.1 | cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands. | May 17, 2022 |
| CVE-2022-28617(opens NVD record) | Critical | 9.8 | A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | May 17, 2022 |
| CVE-2022-28192(opens NVD record) | Medium | 4.1 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges. | May 17, 2022 |
| CVE-2022-28191(opens NVD record) | Medium | 5.5 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service. | May 17, 2022 |
| CVE-2022-28190(opens NVD record) | Medium | 5.5 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper input validation can cause denial of service. | May 17, 2022 |