Export limit exceeded: 387354 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387354 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-33109 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33102 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33100 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33099 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33085 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33084 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2021-33072 | 2025-09-04 | N/A | ||
| This is unused. | ||||
| CVE-2024-36535 | 1 Layer5 | 1 Meshery | 2025-09-03 | 9.8 Critical |
| Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | ||||
| CVE-2024-42050 | 1 Splashtop | 1 Streamer | 2025-09-03 | 7 High |
| The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg. | ||||
| CVE-2024-42051 | 1 Splashtop | 1 Streamer | 2025-09-03 | 7.8 High |
| The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg. | ||||
| CVE-2024-42053 | 1 Splashtop | 1 Streamer | 2025-09-03 | 7.8 High |
| The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a version.dll file in the folder. | ||||
| CVE-2024-45165 | 1 Uci | 1 Idol2 | 2025-09-03 | 5.3 Medium |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key is derived from the string "(c)2007 UCI Software GmbH B.Boll" (without quotes). The key is both static and hardcoded. With access to messages, this results in message decryption and encryption by an attacker. Thus, it enables passive and active man-in-the-middle attacks. | ||||
| CVE-2024-45166 | 1 Uci | 2 Idol2, Idol 2 | 2025-09-03 | 9.8 Critical |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins. | ||||
| CVE-2024-45167 | 1 Uci | 2 Idol2, Idol 2 | 2025-09-03 | 9.8 Critical |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. A certain XmlMessage document causes 100% CPU consumption. | ||||
| CVE-2024-45168 | 1 Uci | 2 Idol2, Idol 2 | 2025-09-03 | 9.1 Critical |
| An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable. | ||||
| CVE-2024-43031 | 2 Autman, Dlink | 2 Autman, Autman | 2025-09-03 | 4.3 Medium |
| autMan v2.9.6 was discovered to contain an access control issue. | ||||
| CVE-2024-43032 | 2 Autman, Dlink | 2 Autman, Autman | 2025-09-03 | 4.3 Medium |
| autMan v2.9.6 allows attackers to bypass authentication via a crafted web request. | ||||
| CVE-2022-34661 | 1 Siemens | 1 Teamcenter | 2025-09-03 | 6.5 Medium |
| A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter is vulnerable to denial of service by entering infinite loops and using up CPU cycles. This could allow an attacker to cause denial of service condition. | ||||
| CVE-2022-2460 | 1 Digital Product Labs | 1 Wpdating | 2025-09-03 | 4.3 Medium |
| The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users | ||||
| CVE-2022-20358 | 1 Google | 1 Android | 2025-09-03 | 7.1 High |
| In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203229608 | ||||