Search

Search Results (47013 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-27568 1 Google 1 Android 2024-11-21 8.1 High
Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
CVE-2022-27567 1 Google 1 Android 2024-11-21 5.9 Medium
Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.
CVE-2022-27563 1 Hcltech 1 Versionvault Express 2024-11-21 7.5 High
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
CVE-2022-27560 1 Hcltech 1 Versionvault Express 2024-11-21 6 Medium
HCL VersionVault Express exposes administrator credentials.
CVE-2022-27558 1 Hcltech 2 Domino, Hcl Inotes 2024-11-21 5.9 Medium
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
CVE-2022-27547 1 Hcltech 2 Domino, Hcl Inotes 2024-11-21 6.1 Medium
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
CVE-2022-27546 1 Hcltech 2 Domino, Hcl Inotes 2024-11-21 8.3 High
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
CVE-2022-27545 1 Hcltech 1 Bigfix Platform 2024-11-21 4.6 Medium
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
CVE-2022-27544 1 Hcltech 1 Bigfix Platform 2024-11-21 5 Medium
BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2022-27535 2 Kaspersky, Microsoft 2 Vpn Secure Connection, Windows 2024-11-21 7.8 High
Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker.
CVE-2022-27532 1 Autodesk 1 3ds Max 2024-11-21 7.8 High
A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.
CVE-2022-27531 1 Autodesk 1 3ds Max 2024-11-21 7.8 High
A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
CVE-2022-27512 1 Citrix 1 Application Delivery Management 2024-11-21 5.3 Medium
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
CVE-2022-27511 1 Citrix 1 Application Delivery Management 2024-11-21 8.1 High
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.
CVE-2022-27463 1 Wwbn 1 Avideo 2024-11-21 6.1 Medium
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
CVE-2022-27462 1 Wwbn 1 Avideo 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.
CVE-2022-27434 1 Unit4 1 Teta 2024-11-21 9.8 Critical
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.
CVE-2022-27373 1 Phicomm 2 Fir303b, Fir303b Firmware 2024-11-21 8.8 High
Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via the Ping function.
CVE-2022-27292 1 Dlink 2 Dir-619, Dir-619 Firmware 2024-11-21 7.5 High
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.
CVE-2022-27250 1 Unisoc 1 Unisoc Chipset 2024-11-21 9.8 Critical
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.