Export limit exceeded: 373843 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373843 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-38538 | 1 Archerydms | 1 Archery | 2024-11-21 | 9.8 Critical |
| Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. | ||||
| CVE-2022-38537 | 1 Archerydms | 1 Archery | 2024-11-21 | 9.8 Critical |
| Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface. | ||||
| CVE-2022-38535 | 1 Totolink | 2 A720r, A720r Firmware | 2024-11-21 | 7.2 High |
| TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function. | ||||
| CVE-2022-38534 | 1 Totolink | 2 A720r, A720r Firmware | 2024-11-21 | 7.2 High |
| TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function. | ||||
| CVE-2022-38533 | 2 Fedoraproject, Gnu | 2 Fedora, Binutils | 2024-11-21 | 5.5 Medium |
| In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file. | ||||
| CVE-2022-38532 | 1 Msi | 1 Center | 2024-11-21 | 7.8 High |
| Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows attackers to escalate privileges via running a crafted executable. | ||||
| CVE-2022-38531 | 1 Fpt | 4 G-97rg3, G-97rg3 Firmware, G-97rg6m and 1 more | 2024-11-21 | 8.8 High |
| FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function. | ||||
| CVE-2022-38530 | 1 Gpac | 1 Gpac | 2024-11-21 | 7.8 High |
| GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD. | ||||
| CVE-2022-38529 | 1 Tinyexr Project | 1 Tinyexr | 2024-11-21 | 7.8 High |
| tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress. | ||||
| CVE-2022-38528 | 1 Assimp | 1 Assimp | 2024-11-21 | 6.5 Medium |
| Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component Assimp::XFileImporter::CreateMeshes. | ||||
| CVE-2022-38511 | 1 Totolink | 2 A810r, A810r Firmware | 2024-11-21 | 7.8 High |
| TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi. | ||||
| CVE-2022-38510 | 1 Tenda | 2 Tx9 Pro, Tx9 Pro Firmware | 2024-11-21 | 7.8 High |
| Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList. | ||||
| CVE-2022-38497 | 1 Lief-project | 1 Lief | 2024-11-21 | 5.5 Medium |
| LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69. | ||||
| CVE-2022-38496 | 1 Lief-project | 1 Lief | 2024-11-21 | 5.5 Medium |
| LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp. | ||||
| CVE-2022-38495 | 1 Lief-project | 1 Lief | 2024-11-21 | 7.8 High |
| LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c. | ||||
| CVE-2022-38493 | 1 Rhonabwy Project | 1 Rhonabwy | 2024-11-21 | 7.5 High |
| Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token. | ||||
| CVE-2022-38485 | 1 Agevolt | 1 Agevolt | 2024-11-21 | 6.5 Medium |
| A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosure. A remote authenticated attacker could leverage this vulnerability to read files from any location on the target operating system with web server privileges. | ||||
| CVE-2022-38484 | 1 Agevolt | 1 Agevolt | 2024-11-21 | 8.8 High |
| An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setup menu in AgeVolt Portal prior to version 0.1. A remote authenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with web server privileges. | ||||
| CVE-2022-38466 | 1 Siemens | 1 Coreshield One-way Gateway | 2024-11-21 | 7.8 High |
| A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file permissions that could allow a local attacker to escalate privileges to local administrator. | ||||
| CVE-2022-38463 | 1 Servicenow | 1 Servicenow | 2024-11-21 | 6.1 Medium |
| ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality. | ||||