Export limit exceeded: 374332 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374332 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-22123 | 1 Fit2cloud | 1 Halo | 2024-11-21 | 5.4 Medium |
| In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server. | ||||
| CVE-2022-22117 | 1 Rangerstudio | 1 Directus | 2024-11-21 | 5.4 Medium |
| In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered. | ||||
| CVE-2022-22116 | 1 Rangerstudio | 1 Directus | 2024-11-21 | 5.4 Medium |
| In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser when they open the image URL. | ||||
| CVE-2022-22115 | 1 Sismics | 1 Teedy | 2024-11-21 | 9 Critical |
| In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low privileged attacker can store malicious scripts in the name of the Tag. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account Takeover of the administrator, and privileges escalation. | ||||
| CVE-2022-22114 | 1 Sismics | 1 Teedy | 2024-11-21 | 9.6 Critical |
| In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary scripts. These scripts are executed in a victim’s browser when they enter the crafted URL. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account Takeover of the administrator, by an unauthenticated attacker. | ||||
| CVE-2022-22113 | 1 Daybydaycrm | 1 Daybyday | 2024-11-21 | 8.8 High |
| In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed. | ||||
| CVE-2022-22112 | 1 Daybydaycrm | 1 Daybyday | 2024-11-21 | 5.4 Medium |
| In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser. | ||||
| CVE-2022-22111 | 1 Daybydaycrm | 1 Daybyday Crm | 2024-11-21 | 8.8 High |
| In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application. | ||||
| CVE-2022-22110 | 1 Daybydaycrm | 1 Daybyday Crm | 2024-11-21 | 7.5 High |
| In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort. | ||||
| CVE-2022-22109 | 1 Daybydaycrm | 1 Daybyday Crm | 2024-11-21 | 5.4 Medium |
| In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victim’s browser when they open the “/tasks” page to view all the tasks. | ||||
| CVE-2022-22108 | 1 Daybydaycrm | 1 Daybyday Crm | 2024-11-21 | 4.3 Medium |
| In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information. | ||||
| CVE-2022-22107 | 1 Daybydaycrm | 1 Daybyday Crm | 2024-11-21 | 4.3 Medium |
| In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all. | ||||
| CVE-2022-22106 | 1 Qualcomm | 4 Sa8540p, Sa8540p Firmware, Sa9000p and 1 more | 2024-11-21 | 8.4 High |
| Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto | ||||
| CVE-2022-22105 | 1 Qualcomm | 102 Apq8009, Apq8009 Firmware, Apq8017 and 99 more | 2024-11-21 | 9.4 Critical |
| Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music | ||||
| CVE-2022-22104 | 1 Qualcomm | 38 Apq8096au, Apq8096au Firmware, Msm8996au and 35 more | 2024-11-21 | 8.4 High |
| Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto | ||||
| CVE-2022-22103 | 1 Qualcomm | 4 Sa8540p, Sa8540p Firmware, Sa9000p and 1 more | 2024-11-21 | 7.8 High |
| Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto | ||||
| CVE-2022-22102 | 1 Qualcomm | 18 Qca6574au, Qca6574au Firmware, Qca6696 and 15 more | 2024-11-21 | 8.4 High |
| Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto | ||||
| CVE-2022-22101 | 1 Qualcomm | 34 Apq8096au, Apq8096au Firmware, Qam8295p and 31 more | 2024-11-21 | 6.2 Medium |
| Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto | ||||
| CVE-2022-22100 | 1 Qualcomm | 34 Apq8096au, Apq8096au Firmware, Qam8295p and 31 more | 2024-11-21 | 8.4 High |
| Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto | ||||
| CVE-2022-22099 | 1 Qualcomm | 4 Sa8540p, Sa8540p Firmware, Sa9000p and 1 more | 2024-11-21 | 8.4 High |
| Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto | ||||