Export limit exceeded: 372898 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372898 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-4502 | 1 Open-emr | 1 Openemr | 2025-04-14 | 6.1 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2. | ||||
| CVE-2022-4446 | 1 Corebos | 1 Corebos | 2025-04-14 | 9.8 Critical |
| PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. | ||||
| CVE-2022-4312 | 1 Arcinformatique | 1 Pcvue | 2025-04-14 | 5.5 Medium |
| A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email account and SIM card. | ||||
| CVE-2022-4311 | 1 Arcinformatique | 1 Pcvue | 2025-04-14 | 4.7 Medium |
| An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources. | ||||
| CVE-2022-4414 | 1 Nuxt | 1 Framework | 2025-04-14 | 6.1 Medium |
| Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | ||||
| CVE-2022-4413 | 1 Nuxt | 1 Framework | 2025-04-14 | 6.1 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13. | ||||
| CVE-2022-4409 | 1 Phpmyfaq | 1 Phpmyfaq | 2025-04-14 | 7.5 High |
| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9. | ||||
| CVE-2022-4408 | 1 Phpmyfaq | 1 Phpmyfaq | 2025-04-14 | 5.4 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9. | ||||
| CVE-2022-4398 | 1 Radare | 1 Radare2 | 2025-04-14 | 7.8 High |
| Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0. | ||||
| CVE-2022-4366 | 1 Daloradius | 1 Daloradius | 2025-04-14 | 7.5 High |
| Missing Authorization in GitHub repository lirantal/daloradius prior to master branch. | ||||
| CVE-2022-4291 | 1 Avast | 1 Script Shield | 2025-04-14 | 7.7 High |
| The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the Script Shield Component. | ||||
| CVE-2022-4261 | 1 Rapid7 | 2 Insightvm, Nexpose | 2025-04-14 | 4.4 Medium |
| Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself. | ||||
| CVE-2022-4314 | 1 Ikus-soft | 1 Rdiffweb | 2025-04-14 | 9.8 Critical |
| Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2. | ||||
| CVE-2022-4173 | 1 Avast | 2 Avast, Avg Antivirus | 2025-04-14 | 7.3 High |
| A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10. | ||||
| CVE-2022-4293 | 1 Vim | 1 Vim | 2025-04-14 | 5.5 Medium |
| Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804. | ||||
| CVE-2022-4292 | 2 Netapp, Vim | 2 Ontap Select Deploy Administration Utility, Vim | 2025-04-14 | 7.8 High |
| Use After Free in GitHub repository vim/vim prior to 9.0.0882. | ||||
| CVE-2022-4271 | 1 Enhancesoft | 1 Osticket | 2025-04-14 | 5.4 Medium |
| Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. | ||||
| CVE-2022-4221 | 1 Asus | 2 Nas-m25, Nas-m25 Firmware | 2025-04-14 | 9.8 Critical |
| Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7. | ||||
| CVE-2022-4136 | 1 Leadshop | 1 Leadshop | 2025-04-14 | 9.8 Critical |
| Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method. | ||||
| CVE-2021-4263 | 1 Leanote | 1 Leanote | 2025-04-14 | 3.5 Low |
| A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. This issue affects the function define of the file public/js/plugins/history.js. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is 0f9733c890077942150696dcc6d2b1482b7a0a19. It is recommended to apply a patch to fix this issue. The identifier VDB-216461 was assigned to this vulnerability. | ||||