Export limit exceeded: 377230 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377230 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-34639 | 1 Openhwgroup | 1 Cva6 | 2024-11-21 | 5.5 Medium |
| CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application. | ||||
| CVE-2022-34637 | 1 Openhwgroup | 1 Cva6 | 2024-11-21 | 5.5 Medium |
| CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded. | ||||
| CVE-2022-34636 | 1 Openhwgroup | 1 Cva6 | 2024-11-21 | 5.5 Medium |
| CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occurs during address translation. | ||||
| CVE-2022-34635 | 1 Openhwgroup | 1 Cva6 | 2024-11-21 | 9.8 Critical |
| The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty. | ||||
| CVE-2022-34634 | 1 Openhwgroup | 1 Cva6 | 2024-11-21 | 5.5 Medium |
| CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception. | ||||
| CVE-2022-34633 | 1 Openhwgroup | 1 Cva6 | 2024-11-21 | 5.5 Medium |
| CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception. | ||||
| CVE-2022-34632 | 1 Linuxfoundation | 1 Rocket Chip Generator | 2024-11-21 | 9.1 Critical |
| Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala. | ||||
| CVE-2022-34625 | 1 Mealie Project | 1 Mealie | 2024-11-21 | 7.2 High |
| Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template. | ||||
| CVE-2022-34624 | 1 Mealie | 1 Mealie | 2024-11-21 | 5.9 Medium |
| Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request. | ||||
| CVE-2022-34621 | 1 Mealie | 1 Mealie | 2024-11-21 | 6.5 Medium |
| Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter. | ||||
| CVE-2022-34619 | 1 Mealie Project | 1 Mealie | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field. | ||||
| CVE-2022-34618 | 1 Mealie Project | 1 Mealie | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field. | ||||
| CVE-2022-34615 | 1 Mealie | 1 Mealie | 2024-11-21 | 9.8 Critical |
| Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. | ||||
| CVE-2022-34613 | 1 Mealie Project | 1 Mealie | 2024-11-21 | 9.8 Critical |
| Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file. | ||||
| CVE-2022-34612 | 1 Rizin | 1 Rizin | 2024-11-21 | 5.5 Medium |
| Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary. | ||||
| CVE-2022-34611 | 1 Online Fire Reporting System Project | 1 Online Fire Reporting System | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field. | ||||
| CVE-2022-34610 | 1 H3c | 2 Magic R200, Magic R200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the URL /ihomers/app. | ||||
| CVE-2022-34609 | 1 H3c | 2 Magic R200, Magic R200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp. | ||||
| CVE-2022-34608 | 1 H3c | 2 Magic R200, Magic R200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ajaxmsg parameter at /AJAX/ajaxget. | ||||
| CVE-2022-34607 | 1 H3c | 2 Magic R200, Magic R200 Firmware | 2024-11-21 | 9.8 Critical |
| H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp. | ||||