Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
73,680 matching · page 1412/1474Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-27260(opens NVD record) | Critical | 9.8 | An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file. | Apr 12, 2022 |
| CVE-2022-21155(opens NVD record) | High | 7.5 | A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. | Apr 12, 2022 |
| CVE-2022-24839(opens NVD record) | High | 7.5 | org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability. | Apr 11, 2022 |
| CVE-2022-22964(opens NVD record) | High | 7.8 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file. | Apr 11, 2022 |
| CVE-2022-22962(opens NVD record) | High | 7.8 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file. | Apr 11, 2022 |
| CVE-2022-22954(opens NVD record) | Critical | 9.8 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution. | Apr 11, 2022 |
| CVE-2022-22572(opens NVD record) | High | 8.8 | A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1. | Apr 11, 2022 |
| CVE-2022-22571(opens NVD record) | Medium | 4.8 | An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions. | Apr 11, 2022 |
| CVE-2022-22258(opens NVD record) | Critical | 9.8 | The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege. | Apr 11, 2022 |
| CVE-2022-22257(opens NVD record) | High | 7.5 | The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity. | Apr 11, 2022 |
| CVE-2022-22256(opens NVD record) | High | 7.5 | The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2022-22255(opens NVD record) | High | 7.5 | The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability. | Apr 11, 2022 |
| CVE-2022-22254(opens NVD record) | High | 7.5 | A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2022-22253(opens NVD record) | High | 7.5 | The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability. | Apr 11, 2022 |
| CVE-2022-1316(opens NVD record) | High | 8.8 | Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation | Apr 11, 2022 |
| CVE-2022-0552(opens NVD record) | Medium | 5.9 | A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11. | Apr 11, 2022 |
| CVE-2021-4047(opens NVD record) | High | 7.5 | The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9. | Apr 11, 2022 |
| CVE-2021-46742(opens NVD record) | Critical | 9.1 | The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability. | Apr 11, 2022 |
| CVE-2021-46740(opens NVD record) | High | 7.5 | The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2021-40065(opens NVD record) | High | 7.5 | The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | Apr 11, 2022 |
| CVE-2021-38125(opens NVD record) | Critical | 9.8 | Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be exploited to unauthenticated remote code execution. | Apr 11, 2022 |
| CVE-2021-22055(opens NVD record) | Medium | 5.3 | The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries. | Apr 11, 2022 |
| CVE-2021-39068(opens NVD record) | Medium | 5.4 | IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215306. | Apr 11, 2022 |
| CVE-2021-38930(opens NVD record) | High | 7.5 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331. | Apr 11, 2022 |
| CVE-2021-38929(opens NVD record) | High | 7.5 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330. | Apr 11, 2022 |
| CVE-2021-37293(opens NVD record) | Medium | 6.5 | A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php. | Apr 11, 2022 |
| CVE-2021-37292(opens NVD record) | High | 7.2 | An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control. | Apr 11, 2022 |
| CVE-2021-37291(opens NVD record) | Critical | 9.8 | An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. | Apr 11, 2022 |
| CVE-2021-40219(opens NVD record) | High | 8.8 | Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution. | Apr 11, 2022 |
| CVE-2022-27115(opens NVD record) | Critical | 9.8 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | Apr 11, 2022 |
| CVE-2022-27088(opens NVD record) | High | 7.8 | Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges. | Apr 11, 2022 |
| CVE-2022-28893(opens NVD record) | High | 7.8 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | Apr 11, 2022 |
| CVE-2022-27883(opens NVD record) | High | 7.3 | A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to exploit this vulnerability. | Apr 9, 2022 |
| CVE-2022-26855(opens NVD record) | Medium | 5.5 | Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability, leading to a denial of service. | Apr 8, 2022 |
| CVE-2022-26854(opens NVD record) | High | 8.1 | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access | Apr 8, 2022 |
| CVE-2022-26852(opens NVD record) | High | 8.1 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise. | Apr 8, 2022 |
| CVE-2022-26851(opens NVD record) | Critical | 9.1 | Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss. | Apr 8, 2022 |
| CVE-2022-24428(opens NVD record) | Medium | 6.3 | Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure. | Apr 8, 2022 |
| CVE-2022-22563(opens NVD record) | Medium | 4.4 | Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes. | Apr 8, 2022 |
| CVE-2021-36293(opens NVD record) | Medium | 6.4 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges. | Apr 8, 2022 |
| CVE-2021-36290(opens NVD record) | Medium | 6.4 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges. | Apr 8, 2022 |
| CVE-2021-36288(opens NVD record) | High | 8.6 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files | Apr 8, 2022 |
| CVE-2021-36287(opens NVD record) | High | 7.3 | Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system. | Apr 8, 2022 |
| CVE-2022-22339(opens NVD record) | High | 7.3 | IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736. | Apr 8, 2022 |
| CVE-2020-4668(opens NVD record) | High | 8.8 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186283. | Apr 8, 2022 |
| CVE-2022-28796(opens NVD record) | High | 7.0 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. | Apr 8, 2022 |
| CVE-2022-24681(opens NVD record) | Medium | 6.1 | Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. | Apr 7, 2022 |
| CVE-2022-26612(opens NVD record) | Critical | 9.8 | In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn't resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3 | Apr 7, 2022 |
| CVE-2022-22516(opens NVD record) | High | 7.8 | The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. | Apr 7, 2022 |
| CVE-2021-43432(opens NVD record) | Medium | 6.1 | A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. | Apr 7, 2022 |