Export limit exceeded: 42461 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (42483 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-20127 1 Google 1 Android 2024-11-21 9.8 Critical
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221862119
CVE-2022-20123 1 Google 1 Android 2024-11-21 7.5 High
In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221852424
CVE-2022-1998 4 Fedoraproject, Linux, Netapp and 1 more 13 Fedora, Linux Kernel, H300s and 10 more 2024-11-21 7.8 High
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
CVE-2022-1993 1 Gogs 1 Gogs 2024-11-21 8.1 High
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1992 2 Gogs, Microsoft 2 Gogs, Windows 2024-11-21 9.1 Critical
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1986 1 Gogs 1 Gogs 2024-11-21 9.8 Critical
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1976 1 Linux 1 Linux Kernel 2024-11-21 7.8 High
A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw within the kernel. This issue leads to memory corruption and possible privilege escalation.
CVE-2022-1975 1 Linux 1 Linux Kernel 2024-11-21 5.5 Medium
There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a nfc device from user-space.
CVE-2022-1974 1 Linux 1 Linux Kernel 2024-11-21 4.1 Medium
A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information.
CVE-2022-1973 3 Fedoraproject, Linux, Netapp 12 Fedora, Linux Kernel, H300s and 9 more 2024-11-21 7.1 High
A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem.
CVE-2022-1958 1 Filecloud 1 Filecloud 2024-11-21 6.3 Medium
A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. Upgrading to version 21.3.5.18513 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-201960.
CVE-2022-1902 1 Redhat 1 Advanced Cluster Security 2024-11-21 8.8 High
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
CVE-2022-1881 1 Octopus 1 Octopus Server 2024-11-21 5.3 Medium
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.
CVE-2022-1853 1 Google 1 Chrome 2024-11-21 9.6 Critical
Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2022-1841 1 Zephyrproject 1 Zephyr 2024-11-21 7.2 High
In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-bounds write a byte zero.
CVE-2022-1825 1 Collectiveaccess 1 Providence 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.
CVE-2022-1816 1 Phpgurukul 1 Zoo Management System 2024-11-21 3.5 Low
A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.
CVE-2022-1814 1 Wp Admin Style Project 1 Wp Admin Style 2024-11-21 4.8 Medium
The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
CVE-2022-1813 1 Rengine Project 1 Rengine 2024-11-21 9.8 Critical
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
CVE-2022-1811 1 Publify Project 1 Publify 2024-11-21 5.4 Medium
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.