Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,624 matching · page 1373/1453Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-22282(opens NVD record) | Critical | 9.8 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability. | May 13, 2022 |
| CVE-2022-22281(opens NVD record) | High | 7.8 | A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system. | May 13, 2022 |
| CVE-2022-1702(opens NVD record) | Medium | 6.1 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability. | May 13, 2022 |
| CVE-2022-1701(opens NVD record) | High | 7.5 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data. | May 13, 2022 |
| CVE-2022-22393(opens NVD record) | Medium | 6.5 | IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078. | May 13, 2022 |
| CVE-2022-22325(opens NVD record) | Medium | 5.5 | IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853. | May 13, 2022 |
| CVE-2022-22252(opens NVD record) | High | 7.5 | The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability. | May 13, 2022 |
| CVE-2022-29796(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-29795(opens NVD record) | High | 7.5 | The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability. | May 13, 2022 |
| CVE-2022-29794(opens NVD record) | Critical | 9.8 | The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality. | May 13, 2022 |
| CVE-2022-29793(opens NVD record) | High | 7.5 | There is a configuration defect in the activation lock of mobile phones.Successful exploitation of this vulnerability may affect application availability. | May 13, 2022 |
| CVE-2022-29792(opens NVD record) | High | 7.5 | The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality. | May 13, 2022 |
| CVE-2022-29791(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-29790(opens NVD record) | High | 7.5 | The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions. | May 13, 2022 |
| CVE-2022-29789(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-28830(opens NVD record) | Medium | 5.5 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28829(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28828(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28827(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28826(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28825(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28824(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28823(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28822(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-28821(opens NVD record) | High | 7.8 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2022 |
| CVE-2022-22261(opens NVD record) | High | 7.5 | The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services. | May 13, 2022 |
| CVE-2022-22260(opens NVD record) | Critical | 9.1 | The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability. | May 13, 2022 |
| CVE-2021-46789(opens NVD record) | High | 7.5 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability. | May 13, 2022 |
| CVE-2021-46788(opens NVD record) | High | 7.5 | Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations. | May 13, 2022 |
| CVE-2021-46787(opens NVD record) | High | 7.5 | The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash. | May 13, 2022 |
| CVE-2021-46786(opens NVD record) | Critical | 9.8 | The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access. | May 13, 2022 |
| CVE-2021-46785(opens NVD record) | Medium | 5.3 | The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier. | May 13, 2022 |
| CVE-2020-22983(opens NVD record) | High | 8.1 | A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task. | May 13, 2022 |
| CVE-2022-25762(opens NVD record) | High | 8.6 | If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors. | May 13, 2022 |
| CVE-2022-23742(opens NVD record) | High | 7.8 | Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. | May 12, 2022 |
| CVE-2022-22971(opens NVD record) | Medium | 6.5 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | May 12, 2022 |
| CVE-2022-22970(opens NVD record) | Medium | 5.3 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | May 12, 2022 |
| CVE-2020-22987(opens NVD record) | Medium | 6.1 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task. | May 12, 2022 |
| CVE-2020-22986(opens NVD record) | Medium | 6.1 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task. | May 12, 2022 |
| CVE-2020-22985(opens NVD record) | Medium | 6.1 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task. | May 12, 2022 |
| CVE-2020-22984(opens NVD record) | Medium | 6.1 | Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task. | May 12, 2022 |
| CVE-2022-29369(opens NVD record) | High | 7.5 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. | May 12, 2022 |
| CVE-2022-28819(opens NVD record) | High | 7.8 | Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file. | May 12, 2022 |
| CVE-2021-22531(opens NVD record) | Medium | 6.1 | A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0 | May 12, 2022 |
| CVE-2022-21151(opens NVD record) | Medium | 5.5 | Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | May 12, 2022 |
| CVE-2021-33117(opens NVD record) | Medium | 5.5 | Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access. | May 12, 2022 |
| CVE-2021-0193(opens NVD record) | High | 7.2 | Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access. | May 12, 2022 |
| CVE-2022-22413(opens NVD record) | Critical | 9.8 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022. | May 12, 2022 |
| CVE-2022-30279(opens NVD record) | High | 7.5 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash. | May 12, 2022 |
| CVE-2022-29885(opens NVD record) | High | 7.5 | The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks. | May 12, 2022 |