Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28817 2022-08-23 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: No impact could be verified. Notes: none.
CVE-2022-36220 1 Ethz 1 Safe Exam Browser 2022-08-22 N/A 9.8 CRITICAL
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
CVE-2022-21807 1 Intel 1 Vtune Profiler 2022-08-22 N/A 7.8 HIGH
Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-26344 1 Intel 1 Single Event Api 2022-08-22 N/A 7.8 HIGH
Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-36225 1 Eyoucms 1 Eyoucms 2022-08-22 N/A 8.8 HIGH
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
CVE-2022-36577 1 Jizhicms 1 Jizhicms 2022-08-22 N/A 8.8 HIGH
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
CVE-2022-37254 1 Dolphinphp Project 1 Dolphinphp 2022-08-22 N/A 5.4 MEDIUM
DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configuration management.
CVE-2022-36579 1 Wellcms 1 Wellcms 2022-08-22 N/A 8.8 HIGH
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-28696 1 Intel 1 Distribution For Python 2022-08-22 N/A 7.8 HIGH
Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-27793 1 Radare 1 Radare2 2022-08-22 N/A 7.5 HIGH
An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack.
CVE-2022-26374 1 Intel 1 Single Event Api 2022-08-22 N/A 7.8 HIGH
Uncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2020-27788 1 Upx Project 1 Upx 2022-08-22 N/A 5.5 MEDIUM
An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service.
CVE-2022-35013 1 Pngdec Project 1 Pngdec 2022-08-22 N/A 6.5 MEDIUM
PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp.
CVE-2022-35012 1 Pngdec Project 1 Pngdec 2022-08-22 N/A 6.5 MEDIUM
PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via SaveBMP at /linux/main.cpp.
CVE-2022-35011 1 Pngdec Project 1 Pngdec 2022-08-22 N/A 8.8 HIGH
PNGDec commit 8abf6be was discovered to contain a global buffer overflow via inflate_fast at /src/inffast.c.
CVE-2022-35010 1 Pngdec Project 1 Pngdec 2022-08-22 N/A 6.5 MEDIUM
PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via asan_interceptors_memintrinsics.cpp.
CVE-2022-35009 1 Pngdec Project 1 Pngdec 2022-08-22 N/A 6.5 MEDIUM
PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp.
CVE-2022-35007 1 Pngdec Project 1 Pngdec 2022-08-22 N/A 6.5 MEDIUM
PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via __interceptor_fwrite.part.57 at sanitizer_common_interceptors.inc.
CVE-2022-35008 1 Pngdec Project 1 Pngdec 2022-08-22 N/A 6.5 MEDIUM
PNGDec commit 8abf6be was discovered to contain a stack overflow via /linux/main.cpp.
CVE-2020-27787 1 Upx Project 1 Upx 2022-08-22 N/A 5.5 MEDIUM
A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.