Search

Search Results (43050 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-27546 1 Hcltech 2 Domino, Hcl Inotes 2024-11-21 8.3 High
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
CVE-2022-27545 1 Hcltech 1 Bigfix Platform 2024-11-21 4.6 Medium
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
CVE-2022-27544 1 Hcltech 1 Bigfix Platform 2024-11-21 5 Medium
BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2022-27535 2 Kaspersky, Microsoft 2 Vpn Secure Connection, Windows 2024-11-21 7.8 High
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
CVE-2022-27463 1 Wwbn 1 Avideo 2024-11-21 6.1 Medium
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
CVE-2022-27462 1 Wwbn 1 Avideo 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.
CVE-2022-27434 1 Unit4 1 Teta 2024-11-21 9.8 Critical
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.
CVE-2022-27373 1 Phicomm 2 Fir303b, Fir303b Firmware 2024-11-21 8.8 High
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via the Ping function.
CVE-2022-27292 1 Dlink 2 Dir-619, Dir-619 Firmware 2024-11-21 7.5 High
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.
CVE-2022-27250 1 Unisoc 1 Unisoc Chipset 2024-11-21 9.8 Critical
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.
CVE-2022-27246 1 Misp 1 Misp 2024-11-21 6.1 Medium
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
CVE-2022-27245 1 Misp 1 Misp 2024-11-21 8.8 High
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.
CVE-2022-27244 1 Misp 1 Misp 2024-11-21 4.8 Medium
An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.
CVE-2022-27243 1 Misp 1 Misp 2024-11-21 7.8 High
An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.
CVE-2022-27240 1 Glewlwyd Sso Server Project 1 Glewlwyd Sso Server 2024-11-21 9.8 Critical
scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.
CVE-2022-27231 1 Veronalabs 1 Wp Statistics 2024-11-21 6.1 Medium
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.
CVE-2022-27225 1 Gradle 1 Enterprise 2024-11-21 6.5 Medium
Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identity management services. During the sign-in process, Keycloak sets browser cookies that effectively provide remember-me functionality. For backwards compatibility with older Safari versions, Keycloak sets a duplicate of the cookie without the Secure attribute, which allows the cookie to be sent when accessing the location that cookie is set for via HTTP. This creates the potential for an attacker (with the ability to impersonate the Gradle Enterprise host) to capture the login session of a user by having them click an http:// link to the server, despite the real server requiring HTTPS.
CVE-2022-27220 1 Siemens 1 Sinema Remote Connect Server 2024-11-21 4.3 Medium
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.
CVE-2022-27219 1 Siemens 1 Sinema Remote Connect Server 2024-11-21 4.3 Medium
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more prone to clickjacking, channel downgrade attacks and other similar client-based attack vectors.
CVE-2022-27218 1 Jenkins 1 Incapptic Connect Uploader 2024-11-21 4.3 Medium
Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.