Export limit exceeded: 374440 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374440 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374440 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-24618 | 1 Heimdalsecurity | 1 Heimdal Premium Security | 2024-11-21 | 7.8 High |
| Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer. | ||||
| CVE-2022-24615 | 1 Zip4j Project | 1 Zip4j | 2024-11-21 | 5.5 Medium |
| zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library. | ||||
| CVE-2022-24612 | 1 Eyesofnetwork | 1 Eyesofnetwork | 2024-11-21 | 5.4 Medium |
| An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS. | ||||
| CVE-2022-24611 | 1 Silabs | 10 Sd3502, Sd3502 Firmware, Sd3503 and 7 more | 2024-11-21 | 6.5 Medium |
| Denial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block S0/S2 protected Z-Wave network via crafted S0 NonceGet Z-Wave packages, utilizing included but absent NodeIDs. | ||||
| CVE-2022-24610 | 1 Alecto | 2 Dvc-215ip, Dvc-215ip Firmware | 2024-11-21 | 8.6 High |
| Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by editing/removing the style of the password field the password becomes visible which grants access to an internal network connected to the camera. | ||||
| CVE-2022-24609 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file. | ||||
| CVE-2022-24608 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 6.1 Medium |
| Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. | ||||
| CVE-2022-24607 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. | ||||
| CVE-2022-24606 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. | ||||
| CVE-2022-24605 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. | ||||
| CVE-2022-24604 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | ||||
| CVE-2022-24603 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. | ||||
| CVE-2022-24602 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | ||||
| CVE-2022-24601 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 High |
| Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements. | ||||
| CVE-2022-24600 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 9.8 Critical |
| Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements. | ||||
| CVE-2022-24595 | 1 Automotivelinux | 1 Kooky Koi | 2024-11-21 | 9.8 Critical |
| Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Control in usr/bin/afb-daemon. To exploit the vulnerability, an attacker should send a well-crafted HTTP (or WebSocket) request to the socket listened by the afb-daemon process. No credentials nor user interactions are required. | ||||
| CVE-2022-24594 | 1 Waline | 1 Waline | 2024-11-21 | 5.3 Medium |
| In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address. | ||||
| CVE-2022-24590 | 1 Backdropcms | 1 Backdrop | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML. | ||||
| CVE-2022-24589 | 1 Burden Project | 1 Burden | 2024-11-21 | 6.1 Medium |
| Burden v3.0 was discovered to contain a stored cross-site scripting (XSS) in the Add Category function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the task parameter. | ||||
| CVE-2022-24588 | 1 Flatpress | 1 Flatpress | 2024-11-21 | 5.4 Medium |
| Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function. | ||||