Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
73,094 matching · page 1408/1462Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-0002(opens NVD record) | Medium | 6.5 | Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | Mar 11, 2022 |
| CVE-2022-0001(opens NVD record) | Medium | 6.5 | Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | Mar 11, 2022 |
| CVE-2021-33658(opens NVD record) | High | 7.8 | atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration. | Mar 11, 2022 |
| CVE-2021-44620(opens NVD record) | Critical | 9.8 | A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters. | Mar 11, 2022 |
| CVE-2022-21819(opens NVD record) | High | 7.6 | NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through the PCI bus. Such an attack could result in denial of service, code execution, escalation of privileges, and impact to data integrity and confidentiality. The scope impact may extend to other components. | Mar 11, 2022 |
| CVE-2020-36518(opens NVD record) | High | 7.5 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | Mar 11, 2022 |
| CVE-2022-0815(opens NVD record) | Medium | 6.5 | Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected. | Mar 10, 2022 |
| CVE-2022-0280(opens NVD record) | High | 7.5 | A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted and potentially cause denial of service. This attack exploits the way symlinks are created and how the product works with them. | Mar 10, 2022 |
| CVE-2021-39025(opens NVD record) | Medium | 5.3 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backend is down. IBM X-Force 213863. | Mar 10, 2022 |
| CVE-2021-39022(opens NVD record) | High | 8.8 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by spreadsheet software. IBM X-Force ID: 213858. | Mar 10, 2022 |
| CVE-2021-38910(opens NVD record) | Medium | 5.3 | IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially crafted JSON message, an attacker could exploit this vulnerability to modify structure and fields. IBM X-Force ID: 209824. | Mar 10, 2022 |
| CVE-2022-26488(opens NVD record) | High | 7.0 | In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2. | Mar 10, 2022 |
| CVE-2022-26355(opens NVD record) | Medium | 4.4 | Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration. | Mar 10, 2022 |
| CVE-2022-25294(opens NVD record) | High | 7.8 | Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges. All versions prior to 7.12.1 are affected. Agents for MacOS and Linux and Cloud are unaffected. Proofpoint has released fixed software version 7.12.1. The fixed software versions are available through the customer support portal. | Mar 10, 2022 |
| CVE-2022-25108(opens NVD record) | Medium | 5.5 | Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation. | Mar 10, 2022 |
| CVE-2022-25090(opens NVD record) | High | 8.1 | Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition. | Mar 10, 2022 |
| CVE-2022-24960(opens NVD record) | Medium | 6.5 | A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data previously allocated on the heap. This issue affects: PDFTron PDFTron SDK 9.2.0 on OSX; 9.2.0 on Linux; 9.2.0 on Windows. | Mar 10, 2022 |
| CVE-2022-24644(opens NVD record) | High | 8.8 | ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse. | Mar 10, 2022 |
| CVE-2022-24618(opens NVD record) | High | 7.8 | Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer. | Mar 10, 2022 |
| CVE-2022-23383(opens NVD record) | Critical | 9.1 | YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out. | Mar 10, 2022 |
| CVE-2022-0891(opens NVD record) | Medium | 6.1 | A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact | Mar 10, 2022 |
| CVE-2022-0865(opens NVD record) | Medium | 5.5 | Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045. | Mar 10, 2022 |
| CVE-2022-0847(opens NVD record) | High | 7.8 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system. | Mar 10, 2022 |
| CVE-2022-0516(opens NVD record) | High | 7.8 | A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4. | Mar 10, 2022 |
| CVE-2021-44750(opens NVD record) | Medium | 6.4 | An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands. | Mar 10, 2022 |
| CVE-2021-41657(opens NVD record) | Medium | 6.1 | SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack. | Mar 10, 2022 |
| CVE-2021-40064(opens NVD record) | High | 7.5 | There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stability. | Mar 10, 2022 |
| CVE-2021-40063(opens NVD record) | High | 7.5 | There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentiality. | Mar 10, 2022 |
| CVE-2021-40062(opens NVD record) | High | 7.5 | There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerability may affect availability. | Mar 10, 2022 |
| CVE-2021-40061(opens NVD record) | High | 7.5 | There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity. | Mar 10, 2022 |
| CVE-2021-40060(opens NVD record) | High | 7.5 | There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability. | Mar 10, 2022 |
| CVE-2021-40059(opens NVD record) | Medium | 6.5 | There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality. | Mar 10, 2022 |
| CVE-2021-40058(opens NVD record) | High | 7.5 | There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability. | Mar 10, 2022 |
| CVE-2021-40057(opens NVD record) | High | 7.5 | There is a heap-based and stack-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability. | Mar 10, 2022 |
| CVE-2021-40056(opens NVD record) | High | 7.5 | There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerability may affect availability. | Mar 10, 2022 |
| CVE-2021-40055(opens NVD record) | Medium | 5.9 | There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity. | Mar 10, 2022 |
| CVE-2021-40054(opens NVD record) | High | 7.5 | There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may affect integrity. | Mar 10, 2022 |
| CVE-2021-40053(opens NVD record) | Critical | 9.1 | There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity. | Mar 10, 2022 |
| CVE-2021-40052(opens NVD record) | High | 7.5 | There is an incorrect buffer size calculation vulnerability in the video framework.Successful exploitation of this vulnerability may affect availability. | Mar 10, 2022 |
| CVE-2021-40051(opens NVD record) | High | 7.5 | There is an unauthorized access vulnerability in system components. Successful exploitation of this vulnerability will affect confidentiality. | Mar 10, 2022 |
| CVE-2021-40050(opens NVD record) | Critical | 9.8 | There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow. | Mar 10, 2022 |
| CVE-2021-40049(opens NVD record) | High | 7.5 | There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization. | Mar 10, 2022 |
| CVE-2021-40048(opens NVD record) | High | 7.5 | There is an incorrect buffer size calculation vulnerability in the video framework. Successful exploitation of this vulnerability will affect availability. | Mar 10, 2022 |
| CVE-2021-40047(opens NVD record) | High | 7.5 | There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity. | Mar 10, 2022 |
| CVE-2021-3739(opens NVD record) | High | 7.1 | A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability. | Mar 10, 2022 |
| CVE-2021-3733(opens NVD record) | Medium | 6.5 | There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability. | Mar 10, 2022 |
| CVE-2021-3698(opens NVD record) | High | 7.5 | A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality. | Mar 10, 2022 |
| CVE-2021-3660(opens NVD record) | Medium | 4.3 | Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks. | Mar 10, 2022 |
| CVE-2021-35251(opens NVD record) | Medium | 5.3 | Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation. | Mar 10, 2022 |
| CVE-2021-20269(opens NVD record) | Medium | 5.5 | A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47. | Mar 10, 2022 |