Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
73,094 matching · page 1405/1462Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2021-3618(opens NVD record) | High | 7.4 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer. | Mar 23, 2022 |
| CVE-2021-3589(opens NVD record) | High | 8.0 | An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | Mar 23, 2022 |
| CVE-2021-46064(opens NVD record) | High | 7.8 | IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image. | Mar 23, 2022 |
| CVE-2022-22316(opens NVD record) | Medium | 6.5 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to incorrectly configured authorization checks. IBM X-Force ID: 218276. | Mar 23, 2022 |
| CVE-2022-0862(opens NVD record) | Low | 3.1 | A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user's password. This functionality was removed from the User Interface in ePO 10 and the API has now been disabled. Other protection is in place to reduce the likelihood of this being successful through sending a link to a logged in user. | Mar 23, 2022 |
| CVE-2022-0861(opens NVD record) | Low | 3.5 | A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data. | Mar 23, 2022 |
| CVE-2022-0859(opens NVD record) | Medium | 6.5 | McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server hosting the ePO server (restricted to administrators) and to know the SQL server password. | Mar 23, 2022 |
| CVE-2022-0858(opens NVD record) | Medium | 4.3 | A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in. | Mar 23, 2022 |
| CVE-2022-0857(opens NVD record) | Medium | 5.4 | A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in. | Mar 23, 2022 |
| CVE-2022-0842(opens NVD record) | Medium | 5.4 | A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges. | Mar 23, 2022 |
| CVE-2021-25220(opens NVD record) | Medium | 6.8 | BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients. | Mar 23, 2022 |
| CVE-2022-0635(opens NVD record) | High | 7.5 | Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check. | Mar 23, 2022 |
| CVE-2022-0396(opens NVD record) | Medium | 5.3 | BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection. | Mar 23, 2022 |
| CVE-2021-45757(opens NVD record) | High | 7.5 | ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS). | Mar 23, 2022 |
| CVE-2021-45756(opens NVD record) | Critical | 9.8 | Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi. | Mar 23, 2022 |
| CVE-2022-27666(opens NVD record) | High | 7.8 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat. | Mar 23, 2022 |
| CVE-2022-25484(opens NVD record) | Medium | 5.5 | tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1. | Mar 22, 2022 |
| CVE-2022-0667(opens NVD record) | High | 7.5 | When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 | Mar 22, 2022 |
| CVE-2022-0652(opens NVD record) | Low | 3.3 | Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710. | Mar 22, 2022 |
| CVE-2022-0386(opens NVD record) | High | 8.8 | A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710. | Mar 22, 2022 |
| CVE-2022-26184(opens NVD record) | Critical | 9.8 | Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS. | Mar 21, 2022 |
| CVE-2022-26183(opens NVD record) | High | 8.8 | PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS. | Mar 21, 2022 |
| CVE-2022-26148(opens NVD record) | Critical | 9.8 | An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address. | Mar 21, 2022 |
| CVE-2022-23352(opens NVD record) | High | 7.5 | An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS). | Mar 21, 2022 |
| CVE-2022-23350(opens NVD record) | Medium | 5.4 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability. | Mar 21, 2022 |
| CVE-2022-23349(opens NVD record) | High | 8.8 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF). | Mar 21, 2022 |
| CVE-2022-23348(opens NVD record) | Medium | 5.3 | BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes. | Mar 21, 2022 |
| CVE-2022-23347(opens NVD record) | High | 7.5 | BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks. | Mar 21, 2022 |
| CVE-2022-23346(opens NVD record) | High | 8.8 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues. | Mar 21, 2022 |
| CVE-2022-23345(opens NVD record) | High | 7.5 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control. | Mar 21, 2022 |
| CVE-2022-22394(opens NVD record) | High | 8.8 | The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrator or node access to the vulnerable server. | Mar 21, 2022 |
| CVE-2022-25578(opens NVD record) | Critical | 9.8 | taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file. | Mar 18, 2022 |
| CVE-2022-24092(opens NVD record) | High | 7.8 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious font file. | Mar 18, 2022 |
| CVE-2022-24091(opens NVD record) | High | 7.8 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious font file. | Mar 18, 2022 |
| CVE-2022-1011(opens NVD record) | High | 7.8 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation. | Mar 18, 2022 |
| CVE-2022-0547(opens NVD record) | Critical | 9.8 | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials. | Mar 18, 2022 |
| CVE-2021-27789(opens NVD record) | Medium | 6.5 | The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An attacker who has compromised the FOS system may utilize this weakness to capture sensitive information, such as user credentials. | Mar 18, 2022 |
| CVE-2020-15388(opens NVD record) | Medium | 6.5 | A vulnerability in the Brocade Fabric OS before Brocade Fabric OS v9.0.1a, v8.2.3, v8.2.0_CBN4, and v7.4.2h could allow an authenticated CLI user to abuse the history command to write arbitrary content to files. | Mar 18, 2022 |
| CVE-2021-39046(opens NVD record) | Medium | 4.9 | IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346. | Mar 18, 2022 |
| CVE-2021-29899(opens NVD record) | Medium | 6.5 | IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413. | Mar 18, 2022 |
| CVE-2022-0742(opens NVD record) | Critical | 9.1 | Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc. | Mar 18, 2022 |
| CVE-2021-45834(opens NVD record) | Critical | 9.8 | An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution. | Mar 18, 2022 |
| CVE-2022-27191(opens NVD record) | High | 7.5 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | Mar 18, 2022 |
| CVE-2021-45868(opens NVD record) | Medium | 5.5 | In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file. | Mar 18, 2022 |
| CVE-2021-44088(opens NVD record) | Critical | 9.8 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters. | Mar 17, 2022 |
| CVE-2021-44087(opens NVD record) | Critical | 9.8 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload. | Mar 17, 2022 |
| CVE-2022-21822(opens NVD record) | High | 7.5 | NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable. | Mar 17, 2022 |
| CVE-2022-26503(opens NVD record) | High | 7.8 | Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges. | Mar 17, 2022 |
| CVE-2022-21221(opens NVD record) | Medium | 5.9 | The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue impacts Windows users only. | Mar 17, 2022 |
| CVE-2022-22273(opens NVD record) | Critical | 9.8 | Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions | Mar 17, 2022 |