Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-22609 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2022-03-24 5.0 MEDIUM 7.5 HIGH
The issue was addressed with additional permissions checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to read other applications' settings.
CVE-2021-46462 1 F5 1 Njs 2022-03-24 5.0 MEDIUM 7.5 HIGH
njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c.
CVE-2021-44087 1 Attendance And Payroll System Project 1 Attendance And Payroll System 2022-03-24 7.5 HIGH 9.8 CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
CVE-2021-29899 1 Ibm 1 Engineering Requirements Quality Assistant On-premises 2022-03-24 4.0 MEDIUM 6.5 MEDIUM
IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413.
CVE-2022-24073 1 Navercorp 1 Whale 2022-03-23 5.8 MEDIUM 7.1 HIGH
The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when users access the store.
CVE-2022-26131 1 Hegemonelectronics 2 Plc4trucks, Plc4trucks Firmware 2022-03-23 7.5 HIGH 9.8 CRITICAL
Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.
CVE-2022-24072 1 Navercorp 1 Whale 2022-03-23 4.3 MEDIUM 6.1 MEDIUM
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
CVE-2021-39710 1 Google 1 Android 2022-03-23 10.0 HIGH 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A
CVE-2021-39709 1 Google 1 Android 2022-03-23 7.2 HIGH 7.8 HIGH
In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208817618
CVE-2021-39737 1 Google 1 Android 2022-03-23 10.0 HIGH 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A
CVE-2022-22600 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2022-03-23 4.3 MEDIUM 5.5 MEDIUM
The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.
CVE-2022-0430 1 Httpie 1 Httpie 2022-03-23 5.0 MEDIUM 5.3 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.
CVE-2021-39720 1 Google 1 Android 2022-03-22 10.0 HIGH 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A
CVE-2021-39716 1 Google 1 Android 2022-03-22 5.0 MEDIUM 7.5 HIGH
Product: AndroidVersions: Android kernelAndroid ID: A-206977562References: N/A
CVE-2021-39723 1 Google 1 Android 2022-03-22 10.0 HIGH 9.8 CRITICAL
Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A
CVE-2020-36519 1 Mimecast 1 Email Security 2022-03-22 4.0 MEDIUM 4.9 MEDIUM
Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.)
CVE-2022-22354 2 Ibm, Linux 3 Spectrum Copy Data Management, Spectrum Protect Plus, Linux Kernel 2022-03-22 5.0 MEDIUM 7.5 HIGH
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.
CVE-2022-22353 2 Cloudera, Ibm 3 Data Platform, Big Sql, Cloud Pak For Data 2022-03-22 4.0 MEDIUM 6.5 MEDIUM
IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate permissions to obtain sensitive information by bypassing data masking rules using a CREATE TABLE SELECT statement. IBM X-Force ID: 220480.
CVE-2022-25511 1 Freetakserver-ui Project 1 Freetakserver-ui 2022-03-22 4.0 MEDIUM 6.5 MEDIUM
An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.
CVE-2022-23924 1 Hp 1 Pc Bios 2022-03-21 7.2 HIGH 8.2 HIGH
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.