Export limit exceeded: 373686 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373686 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-1050 | 1 Qemu | 1 Qemu | 2024-11-21 | 8.8 High |
| A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition. | ||||
| CVE-2022-1049 | 3 Clusterlabs, Debian, Redhat | 3 Pcs, Debian Linux, Enterprise Linux | 2024-11-21 | 8.8 High |
| A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login. | ||||
| CVE-2022-1048 | 4 Debian, Linux, Netapp and 1 more | 22 Debian Linux, Linux Kernel, H300e and 19 more | 2024-11-21 | 7.0 High |
| A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system. | ||||
| CVE-2022-1047 | 1 Themify | 1 Post Type Builder Search Addon | 2024-11-21 | 6.1 Medium |
| The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability. | ||||
| CVE-2022-1046 | 1 Vfbpro | 1 Visual Form Builder | 2024-11-21 | 4.8 Medium |
| The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||||
| CVE-2022-1045 | 1 Trudesk Project | 1 Trudesk | 2024-11-21 | 5.4 Medium |
| Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0. | ||||
| CVE-2022-1044 | 1 Trudesk Project | 1 Trudesk | 2024-11-21 | 6.5 Medium |
| Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1. | ||||
| CVE-2022-1043 | 1 Linux | 1 Linux Kernel | 2024-11-21 | 8.8 High |
| A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges. | ||||
| CVE-2022-1042 | 1 Zephyrproject | 1 Zephyr | 2024-11-21 | 8.2 High |
| In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. | ||||
| CVE-2022-1041 | 1 Zephyrproject | 1 Zephyr | 2024-11-21 | 8.2 High |
| In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. | ||||
| CVE-2022-1037 | 1 Villatheme | 1 Exmage | 2024-11-21 | 7.2 High |
| The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs | ||||
| CVE-2022-1036 | 1 Microweber | 1 Microweber | 2024-11-21 | 7.5 High |
| Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12. | ||||
| CVE-2022-1035 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||||
| CVE-2022-1034 | 1 Showdoc | 1 Showdoc | 2024-11-21 | 7.2 High |
| There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4. | ||||
| CVE-2022-1033 | 1 Craterapp | 1 Crater | 2024-11-21 | 7.8 High |
| Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | ||||
| CVE-2022-1032 | 1 Craterapp | 1 Crater | 2024-11-21 | 7.2 High |
| Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | ||||
| CVE-2022-1031 | 1 Radare | 1 Radare2 | 2024-11-21 | 7.8 High |
| Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6. | ||||
| CVE-2022-1030 | 3 Apple, Linux, Okta | 3 Macos, Linux Kernel, Advanced Server Access | 2024-11-21 | 8.8 High |
| Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local system. | ||||
| CVE-2022-1029 | 1 Miniorange | 1 Limit Login Attempts | 2024-11-21 | 4.8 Medium |
| The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup) | ||||
| CVE-2022-1028 | 1 Miniorange | 1 Wordpress Security | 2024-11-21 | 4.8 Medium |
| The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup) | ||||