Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
73,094 matching · page 1404/1462Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2003-5003(opens NVD record) | Medium | 5.0 | A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipulation with an unknown input leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | Mar 28, 2022 |
| CVE-2003-5002(opens NVD record) | Low | 3.7 | A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update Handler which allows cleartext transmission of data. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | Mar 28, 2022 |
| CVE-2003-5001(opens NVD record) | Medium | 5.3 | A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE/OPTIONS Request leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | Mar 28, 2022 |
| CVE-2022-1056(opens NVD record) | Medium | 5.5 | Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd. | Mar 28, 2022 |
| CVE-2022-26258(opens NVD record) | Critical | 9.8 | D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. | Mar 28, 2022 |
| CVE-2022-27942(opens NVD record) | High | 7.8 | tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. | Mar 26, 2022 |
| CVE-2022-27941(opens NVD record) | High | 7.8 | tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c. | Mar 26, 2022 |
| CVE-2022-27940(opens NVD record) | High | 7.8 | tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. | Mar 26, 2022 |
| CVE-2022-27939(opens NVD record) | Medium | 5.5 | tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. | Mar 26, 2022 |
| CVE-2022-22274(opens NVD record) | Critical | 9.8 | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall. | Mar 25, 2022 |
| CVE-2021-40906(opens NVD record) | Medium | 6.1 | CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication. | Mar 25, 2022 |
| CVE-2021-40905(opens NVD record) | High | 8.8 | The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this manner. | Mar 25, 2022 |
| CVE-2021-40904(opens NVD record) | High | 8.8 | The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator. | Mar 25, 2022 |
| CVE-2022-26659(opens NVD record) | High | 7.1 | Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users. | Mar 25, 2022 |
| CVE-2022-26197(opens NVD record) | Medium | 5.4 | Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table. | Mar 25, 2022 |
| CVE-2022-25523(opens NVD record) | High | 8.8 | TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request. | Mar 25, 2022 |
| CVE-2022-25590(opens NVD record) | Medium | 6.5 | SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application. | Mar 25, 2022 |
| CVE-2022-0995(opens NVD record) | High | 7.8 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system. | Mar 25, 2022 |
| CVE-2022-0897(opens NVD record) | Medium | 4.3 | A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd). | Mar 25, 2022 |
| CVE-2022-0759(opens NVD record) | High | 8.1 | A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM). | Mar 25, 2022 |
| CVE-2022-0500(opens NVD record) | High | 7.8 | A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system. | Mar 25, 2022 |
| CVE-2022-0435(opens NVD record) | High | 8.8 | A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network. | Mar 25, 2022 |
| CVE-2022-0330(opens NVD record) | High | 7.8 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system. | Mar 25, 2022 |
| CVE-2022-0322(opens NVD record) | Medium | 5.5 | A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS). | Mar 25, 2022 |
| CVE-2021-4203(opens NVD record) | Medium | 6.8 | A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information. | Mar 25, 2022 |
| CVE-2021-4157(opens NVD record) | High | 8.0 | An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system. | Mar 25, 2022 |
| CVE-2021-4147(opens NVD record) | Medium | 6.5 | A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. | Mar 25, 2022 |
| CVE-2021-3941(opens NVD record) | Medium | 6.5 | In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked with OpenEXR. | Mar 25, 2022 |
| CVE-2021-3814(opens NVD record) | High | 7.5 | It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure. | Mar 25, 2022 |
| CVE-2021-35254(opens NVD record) | High | 8.2 | SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future. | Mar 25, 2022 |
| CVE-2021-26622(opens NVD record) | Critical | 9.6 | An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability. | Mar 25, 2022 |
| CVE-2021-20323(opens NVD record) | Medium | 6.1 | A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. | Mar 25, 2022 |
| CVE-2022-26263(opens NVD record) | Medium | 6.1 | Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp. | Mar 25, 2022 |
| CVE-2022-25574(opens NVD record) | Medium | 4.8 | A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file. | Mar 25, 2022 |
| CVE-2022-1040(opens NVD record) | Critical | 9.8 | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older. | Mar 25, 2022 |
| CVE-2018-25032(opens NVD record) | High | 7.5 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | Mar 25, 2022 |
| CVE-2022-22374(opens NVD record) | Critical | 9.1 | The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its host. IBM X-Force ID: 221442. | Mar 24, 2022 |
| CVE-2022-21820(opens NVD record) | Medium | 6.3 | NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data confidentiality and integrity. | Mar 24, 2022 |
| CVE-2022-26629(opens NVD record) | Critical | 9.1 | An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function. | Mar 24, 2022 |
| CVE-2021-44226(opens NVD record) | High | 7.3 | Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there. | Mar 23, 2022 |
| CVE-2022-24293(opens NVD record) | Critical | 9.8 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | Mar 23, 2022 |
| CVE-2022-24292(opens NVD record) | Critical | 9.8 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | Mar 23, 2022 |
| CVE-2022-24291(opens NVD record) | High | 7.5 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | Mar 23, 2022 |
| CVE-2022-22952(opens NVD record) | Critical | 9.1 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file. | Mar 23, 2022 |
| CVE-2022-22951(opens NVD record) | Critical | 9.1 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution. | Mar 23, 2022 |
| CVE-2022-1030(opens NVD record) | High | 8.8 | Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system. | Mar 23, 2022 |
| CVE-2022-0996(opens NVD record) | Medium | 6.5 | A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. | Mar 23, 2022 |
| CVE-2021-4197(opens NVD record) | High | 7.8 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system. | Mar 23, 2022 |
| CVE-2021-4180(opens NVD record) | Medium | 4.3 | An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid in additional system exploitation. This flaw affects openstack-tripleo-heat-templates versions prior to 11.6.1. | Mar 23, 2022 |
| CVE-2021-3748(opens NVD record) | High | 7.5 | A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process. | Mar 23, 2022 |