Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41530 1 Open Source Sacco Management System Project 1 Open Source Sacco Management System 2022-10-13 N/A 7.2 HIGH
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower.
CVE-2022-37980 1 Microsoft 3 Windows 10, Windows 11, Windows Server 2022 2022-10-13 N/A 7.8 HIGH
Windows DHCP Client Elevation of Privilege Vulnerability.
CVE-2022-41407 1 Online Pet Shop We App Project 1 Online Pet Shop We App 2022-10-13 N/A 7.2 HIGH
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
CVE-2022-41408 1 Online Pet Shop We App Project 1 Online Pet Shop We App 2022-10-13 N/A 9.8 CRITICAL
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
CVE-2022-20437 1 Google 1 Android 2022-10-13 N/A 5.5 MEDIUM
In Messaging, There has unauthorized broadcast, this could cause Local Deny of Service.Product: AndroidVersions: Android SoCAndroid ID: A-242258929
CVE-2022-20436 1 Google 1 Android 2022-10-13 N/A 7.8 HIGH
There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369
CVE-2022-37979 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2022-10-13 N/A 7.8 HIGH
Windows Hyper-V Elevation of Privilege Vulnerability.
CVE-2022-40921 1 Dedecms 1 Dedecms 2022-10-13 N/A 7.2 HIGH
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.
CVE-2022-40494 1 Nps Project 1 Nps 2022-10-13 N/A 9.8 CRITICAL
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.
CVE-2022-37999 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-10-13 N/A 7.8 HIGH
Windows Group Policy Preference Client Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37993, CVE-2022-37994.
CVE-2022-37998 1 Microsoft 3 Windows 10, Windows 11, Windows Server 2022 2022-10-13 N/A 7.7 HIGH
Windows Local Session Manager (LSM) Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-37973.
CVE-2020-14129 1 Mi 1 Xiaomi 2022-10-13 N/A 9.8 CRITICAL
A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.
CVE-2020-14131 1 Mi 1 Xiaomi 2022-10-13 N/A 9.8 CRITICAL
The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi users worldwide Life.
CVE-2022-21936 1 Johnsoncontrols 2 Metasys Extended Application And Data Server, Metasys For Validated Environments 2022-10-13 N/A 6.5 MEDIUM
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
CVE-2022-38000 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2022-10-13 N/A 8.1 HIGH
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22035, CVE-2022-24504, CVE-2022-30198, CVE-2022-33634, CVE-2022-38047, CVE-2022-41081.
CVE-2022-37208 1 Jflyfox 1 Jfinal Cms 2022-10-13 N/A 8.8 HIGH
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
CVE-2018-17954 1 Suse 2 Openstack Cloud, Openstack Cloud Crowbar 2022-10-13 7.2 HIGH 7.8 HIGH
An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9 allows root users on any crowbar managed node to cause become root on any other node. This issue affects: SUSE OpenStack Cloud 7 crowbar-core versions prior to 4.0+git.1578392992.fabfd186c-9.63.1, crowbar-. SUSE OpenStack Cloud 8 ardana-cinder versions prior to 8.0+git.1579279939.ee7da88-3.39.3, ardana-. SUSE OpenStack Cloud 9 ardana-ansible versions prior to 9.0+git.1581611758.f694f7d-3.16.1, ardana-. SUSE OpenStack Cloud Crowbar 8 crowbar-core versions prior to 5.0+git.1582968668.1a55c77c5-3.35.4, crowbar-. SUSE OpenStack Cloud Crowbar 9 crowbar-core versions prior to 6.0+git.1582892022.cbd70e833-3.19.3, crowbar-.
CVE-2022-3458 1 Human Resource Management System Project 1 Human Resource Management System 2022-10-12 N/A 9.8 CRITICAL
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.
CVE-2022-20429 1 Google 1 Android 2022-10-12 N/A 8.8 HIGH
In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220741473
CVE-2022-20425 1 Google 1 Android 2022-10-12 N/A 5.5 MEDIUM
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235823407