Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
73,094 matching · page 1403/1462Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2019-14839(opens NVD record) | High | 7.5 | It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. | Apr 1, 2022 |
| CVE-2022-24426(opens NVD record) | High | 7.8 | Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation. | Apr 1, 2022 |
| CVE-2022-23158(opens NVD record) | Medium | 6.0 | Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user with standard privilege could potentially exploit this vulnerability and provide incorrect port information and get connected to valid WMS server | Apr 1, 2022 |
| CVE-2022-23157(opens NVD record) | Medium | 4.4 | Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious user could potentially exploit this vulnerability in order to view sensitive information from the WMS Server. | Apr 1, 2022 |
| CVE-2022-23156(opens NVD record) | Medium | 6.0 | Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could potentially exploit this vulnerability by providing invalid input in order to obtain a connection to WMS server. | Apr 1, 2022 |
| CVE-2022-23155(opens NVD record) | High | 7.2 | Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system. | Apr 1, 2022 |
| CVE-2022-22404(opens NVD record) | Medium | 6.5 | IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulnerable to denial of service due to excessive rate limiting. | Apr 1, 2022 |
| CVE-2022-22332(opens NVD record) | High | 7.5 | IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131. | Apr 1, 2022 |
| CVE-2022-22331(opens NVD record) | High | 7.1 | IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130. | Apr 1, 2022 |
| CVE-2022-22328(opens NVD record) | Medium | 6.2 | IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data. IBM X-Force ID: 218871. | Apr 1, 2022 |
| CVE-2022-22327(opens NVD record) | High | 7.5 | IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859. | Apr 1, 2022 |
| CVE-2022-27966(opens NVD record) | Medium | 6.5 | Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | Mar 31, 2022 |
| CVE-2022-27965(opens NVD record) | Medium | 6.5 | Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | Mar 31, 2022 |
| CVE-2022-27964(opens NVD record) | Medium | 6.5 | Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | Mar 31, 2022 |
| CVE-2022-27963(opens NVD record) | Medium | 6.5 | Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | Mar 31, 2022 |
| CVE-2022-27050(opens NVD record) | High | 7.8 | BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level. | Mar 31, 2022 |
| CVE-2022-24794(opens NVD record) | High | 7.5 | Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is applied to a catch all route. If all routes under `example.com` are protected with the `requiresAuth` middleware, a visit to `http://example.com//google.com` will be redirected to `google.com` after login because the original url reported by the Express framework is not properly sanitized. This vulnerability affects versions prior to 2.7.2. Users are advised to upgrade. There are no known workarounds. | Mar 31, 2022 |
| CVE-2022-22311(opens NVD record) | Medium | 6.5 | IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens. | Mar 31, 2022 |
| CVE-2021-42868(opens NVD record) | Medium | 4.8 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. . | Mar 31, 2022 |
| CVE-2022-28128(opens NVD record) | High | 7.8 | Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory. | Mar 31, 2022 |
| CVE-2022-25348(opens NVD record) | High | 7.8 | Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory. | Mar 31, 2022 |
| CVE-2022-26646(opens NVD record) | Critical | 9.8 | Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter. | Mar 30, 2022 |
| CVE-2022-26645(opens NVD record) | Critical | 9.8 | A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function. | Mar 30, 2022 |
| CVE-2022-26644(opens NVD record) | Medium | 6.1 | Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management. | Mar 30, 2022 |
| CVE-2021-46010(opens NVD record) | High | 8.8 | Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations. | Mar 30, 2022 |
| CVE-2021-46009(opens NVD record) | Critical | 9.8 | In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies. | Mar 30, 2022 |
| CVE-2021-46008(opens NVD record) | High | 8.8 | In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on. | Mar 30, 2022 |
| CVE-2021-46007(opens NVD record) | Critical | 9.8 | totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks. | Mar 30, 2022 |
| CVE-2021-46006(opens NVD record) | Medium | 6.5 | In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication. | Mar 30, 2022 |
| CVE-2021-38362(opens NVD record) | Medium | 6.5 | In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data. | Mar 30, 2022 |
| CVE-2022-27772(opens NVD record) | High | 7.8 | spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer supported by the maintainer | Mar 30, 2022 |
| CVE-2022-22772(opens NVD record) | High | 8.5 | The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX and TIBCO Managed File Transfer Platform Server for z/Linux contain a difficult to exploit Remote Code Execution (RCE) vulnerability that allows a low privileged attacker with network access to execute arbitrary code on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX: versions 8.1.0 and below and TIBCO Managed File Transfer Platform Server for z/Linux: versions 8.1.0 and below. | Mar 30, 2022 |
| CVE-2022-0998(opens NVD record) | High | 7.8 | An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system. | Mar 30, 2022 |
| CVE-2020-35501(opens NVD record) | Low | 3.4 | A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem | Mar 30, 2022 |
| CVE-2022-1154(opens NVD record) | High | 7.8 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. | Mar 30, 2022 |
| CVE-2022-26951(opens NVD record) | Medium | 6.5 | Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application. | Mar 30, 2022 |
| CVE-2022-26950(opens NVD record) | Medium | 5.4 | Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred. | Mar 30, 2022 |
| CVE-2022-26949(opens NVD record) | Medium | 5.3 | Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowed by extra privileges. | Mar 30, 2022 |
| CVE-2022-26948(opens NVD record) | Medium | 5.8 | The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks. | Mar 30, 2022 |
| CVE-2022-26947(opens NVD record) | Medium | 6.3 | Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application. | Mar 30, 2022 |
| CVE-2022-26244(opens NVD record) | Medium | 5.4 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field. | Mar 30, 2022 |
| CVE-2021-41594(opens NVD record) | Medium | 6.5 | In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions. | Mar 30, 2022 |
| CVE-2022-26871(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution. | Mar 29, 2022 |
| CVE-2022-21821(opens NVD record) | High | 7.8 | NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity. | Mar 29, 2022 |
| CVE-2022-22948(opens NVD record) | Medium | 6.5 | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. | Mar 29, 2022 |
| CVE-2022-1055(opens NVD record) | High | 7.8 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 | Mar 29, 2022 |
| CVE-2022-28148(opens NVD record) | Medium | 6.5 | The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents of arbitrary files on Windows controllers. | Mar 29, 2022 |
| CVE-2022-25521(opens NVD record) | Critical | 9.8 | NUUO v03.11.00 was discovered to contain access control issue. | Mar 29, 2022 |
| CVE-2022-0331(opens NVD record) | Medium | 5.3 | An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older. | Mar 29, 2022 |
| CVE-2005-10001(opens NVD record) | Medium | 5.4 | A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | Mar 28, 2022 |