Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,544 matching · page 1389/1451Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-23159(opens NVD record) | Medium | 4.8 | Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contain a missing release of memory after effective lifetime vulnerability. An authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE and ISI_PRIV_AUTH_PROVIDERS privileges could exploit this vulnerability, leading to a Denial-Of-Service. This can also impact a cluster in Compliance mode. Dell recommends to update at the earliest opportunity. | Apr 12, 2022 |
| CVE-2022-22565(opens NVD record) | Medium | 4.7 | Dell PowerScale OneFS, versions 9.0.0-9.3.0, contain an improper authorization of index containing sensitive information. An authenticated and privileged user could potentially exploit this vulnerability, leading to disclosure or modification of sensitive data. | Apr 12, 2022 |
| CVE-2022-22562(opens NVD record) | High | 7.5 | Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker could potentially exploit this denial-of-service vulnerability. | Apr 12, 2022 |
| CVE-2022-22561(opens NVD record) | High | 8.1 | Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts. | Apr 12, 2022 |
| CVE-2022-22560(opens NVD record) | High | 7.1 | Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch offline. | Apr 12, 2022 |
| CVE-2022-22559(opens NVD record) | High | 7.5 | Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm. An unprivileged network attacker could exploit this vulnerability, leading to the potential for information disclosure. | Apr 12, 2022 |
| CVE-2022-22550(opens NVD record) | Medium | 6.7 | Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over. | Apr 12, 2022 |
| CVE-2022-22549(opens NVD record) | High | 7.5 | Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials. | Apr 12, 2022 |
| CVE-2022-28397(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional. | Apr 12, 2022 |
| CVE-2022-27262(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file. | Apr 12, 2022 |
| CVE-2022-27260(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file. | Apr 12, 2022 |
| CVE-2022-21155(opens NVD record) | High | 7.5 | A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. | Apr 12, 2022 |
| CVE-2022-24839(opens NVD record) | High | 7.5 | org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability. | Apr 11, 2022 |
| CVE-2022-22964(opens NVD record) | High | 7.8 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file. | Apr 11, 2022 |
| CVE-2022-22962(opens NVD record) | High | 7.8 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file. | Apr 11, 2022 |
| CVE-2022-22954(opens NVD record) | Critical | 9.8 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | Apr 11, 2022 |
| CVE-2022-22572(opens NVD record) | High | 8.8 | A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1. | Apr 11, 2022 |
| CVE-2022-22571(opens NVD record) | Medium | 4.8 | An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions. | Apr 11, 2022 |
| CVE-2022-22258(opens NVD record) | Critical | 9.8 | The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege. | Apr 11, 2022 |
| CVE-2022-22257(opens NVD record) | High | 7.5 | The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity. | Apr 11, 2022 |
| CVE-2022-22256(opens NVD record) | High | 7.5 | The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2022-22255(opens NVD record) | High | 7.5 | The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability. | Apr 11, 2022 |
| CVE-2022-22254(opens NVD record) | High | 7.5 | A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2022-22253(opens NVD record) | High | 7.5 | The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability. | Apr 11, 2022 |
| CVE-2022-1316(opens NVD record) | High | 8.8 | Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation | Apr 11, 2022 |
| CVE-2022-0552(opens NVD record) | Medium | 5.9 | A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11. | Apr 11, 2022 |
| CVE-2021-4047(opens NVD record) | High | 7.5 | The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9. | Apr 11, 2022 |
| CVE-2021-46742(opens NVD record) | Critical | 9.1 | The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability. | Apr 11, 2022 |
| CVE-2021-46740(opens NVD record) | High | 7.5 | The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2021-40065(opens NVD record) | High | 7.5 | The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2021-38125(opens NVD record) | Critical | 9.8 | Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be exploited to unauthenticated remote code execution. | Apr 11, 2022 |
| CVE-2021-22055(opens NVD record) | Medium | 5.3 | The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries. | Apr 11, 2022 |
| CVE-2021-39068(opens NVD record) | Medium | 5.4 | IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215306. | Apr 11, 2022 |
| CVE-2021-38930(opens NVD record) | High | 7.5 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331. | Apr 11, 2022 |
| CVE-2021-38929(opens NVD record) | High | 7.5 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330. | Apr 11, 2022 |
| CVE-2021-37293(opens NVD record) | Medium | 6.5 | A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php. | Apr 11, 2022 |
| CVE-2021-37292(opens NVD record) | High | 7.2 | An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control. | Apr 11, 2022 |
| CVE-2021-37291(opens NVD record) | Critical | 9.8 | An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. | Apr 11, 2022 |
| CVE-2021-40219(opens NVD record) | High | 8.8 | Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution. | Apr 11, 2022 |
| CVE-2022-27115(opens NVD record) | Critical | 9.8 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | Apr 11, 2022 |
| CVE-2022-27088(opens NVD record) | High | 7.8 | Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges. | Apr 11, 2022 |
| CVE-2022-28893(opens NVD record) | High | 7.8 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | Apr 11, 2022 |
| CVE-2022-27883(opens NVD record) | High | 7.3 | A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to exploit this vulnerability. | Apr 9, 2022 |
| CVE-2022-26855(opens NVD record) | Medium | 5.5 | Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability, leading to a denial of service. | Apr 8, 2022 |
| CVE-2022-26854(opens NVD record) | High | 8.1 | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access | Apr 8, 2022 |
| CVE-2022-26852(opens NVD record) | High | 8.1 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise. | Apr 8, 2022 |
| CVE-2022-26851(opens NVD record) | Critical | 9.1 | Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss. | Apr 8, 2022 |
| CVE-2022-24428(opens NVD record) | Medium | 6.3 | Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure. | Apr 8, 2022 |
| CVE-2022-22563(opens NVD record) | Medium | 4.4 | Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes. | Apr 8, 2022 |
| CVE-2021-36293(opens NVD record) | Medium | 6.4 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges. | Apr 8, 2022 |