Export limit exceeded: 365306 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (365306 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-43514 | 1 Siemens | 1 Automation License Manager | 2025-04-09 | 7.7 High |
| A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations, allowing to modify files and folders outside the intended root directory. This could allow an unauthenticated remote attacker to execute file operations of files outside of the specified root folder. Chained with CVE-2022-43513 this could allow Remote Code Execution. | ||||
| CVE-2025-20658 | 2 Google, Mediatek | 19 Android, Mt2718, Mt6781 and 16 more | 2025-04-09 | 6 Medium |
| In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597. | ||||
| CVE-2022-4863 | 1 Usememos | 1 Memos | 2025-04-09 | 6.5 Medium |
| Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1. | ||||
| CVE-2023-0091 | 1 Redhat | 4 Keycloak, Red Hat Single Sign On, Rhosemc and 1 more | 2025-04-09 | 3.8 Low |
| A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information. | ||||
| CVE-2022-47866 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. | ||||
| CVE-2022-47865 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. | ||||
| CVE-2022-47864 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. | ||||
| CVE-2022-47862 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. | ||||
| CVE-2022-47861 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. | ||||
| CVE-2022-47860 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. | ||||
| CVE-2022-47859 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php. | ||||
| CVE-2022-47790 | 1 Dynamic Transaction Queuing System Project | 1 Dynamic Transaction Queuing System | 2025-04-09 | 9.8 Critical |
| Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=. | ||||
| CVE-2022-46603 | 1 Inkdrop | 1 Inkdrop | 2025-04-09 | 6.1 Medium |
| An issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file. | ||||
| CVE-2022-40519 | 1 Qualcomm | 386 Aqt1000, Aqt1000 Firmware, Ar8031 and 383 more | 2025-04-09 | 6.8 Medium |
| Information disclosure due to buffer overread in Core | ||||
| CVE-2022-40518 | 1 Qualcomm | 320 Aqt1000, Aqt1000 Firmware, Ar8031 and 317 more | 2025-04-09 | 6.8 Medium |
| Information disclosure due to buffer overread in Core | ||||
| CVE-2022-40517 | 1 Qualcomm | 362 Aqt1000, Aqt1000 Firmware, Ar8031 and 359 more | 2025-04-09 | 8.4 High |
| Memory corruption in core due to stack-based buffer overflow | ||||
| CVE-2022-40516 | 1 Qualcomm | 368 Aqt1000, Aqt1000 Firmware, Ar8031 and 365 more | 2025-04-09 | 8.4 High |
| Memory corruption in Core due to stack-based buffer overflow. | ||||
| CVE-2022-33300 | 1 Qualcomm | 102 Qam8295p, Qam8295p Firmware, Qca6174a and 99 more | 2025-04-09 | 8.4 High |
| Memory corruption in Automotive Android OS due to improper input validation. | ||||
| CVE-2022-33299 | 1 Qualcomm | 88 Apq8017, Apq8017 Firmware, Apq8096au and 85 more | 2025-04-09 | 7.5 High |
| Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data. | ||||
| CVE-2022-33290 | 1 Qualcomm | 92 Apq8017, Apq8017 Firmware, Apq8096au and 89 more | 2025-04-09 | 7.5 High |
| Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed. | ||||