Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-1042 | 1 Zephyrproject | 1 Zephyr | 2022-08-03 | N/A | 8.8 HIGH |
In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. | |||||
CVE-2022-34529 | 1 Wasm3 Project | 1 Wasm3 | 2022-08-03 | N/A | 5.5 MEDIUM |
WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill. | |||||
CVE-2022-33970 | 1 Oxilab | 1 Shortcode Addons | 2022-08-03 | N/A | 7.2 HIGH |
Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress. | |||||
CVE-2022-34009 | 2 Fossil-scm, Microsoft | 2 Fossil, Windows | 2022-08-03 | N/A | 5.5 MEDIUM |
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware. | |||||
CVE-2022-22476 | 1 Ibm | 2 Open Liberty, Websphere Application Server | 2022-08-03 | 6.0 MEDIUM | 8.8 HIGH |
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604. | |||||
CVE-2022-24406 | 1 Open-xchange | 1 Ox App Suite | 2022-08-03 | N/A | 6.5 MEDIUM |
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls. | |||||
CVE-2022-34577 | 1 Wavlink | 2 Wn535g3, Wn535g3 Firmware | 2022-08-03 | N/A | 9.8 CRITICAL |
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request. | |||||
CVE-2022-24405 | 1 Open-xchange | 1 Ox App Suite | 2022-08-03 | N/A | 9.8 CRITICAL |
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | |||||
CVE-2022-23101 | 1 Open-xchange | 1 Ox App Suite | 2022-08-03 | N/A | 6.1 MEDIUM |
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message. | |||||
CVE-2022-23100 | 1 Open-xchange | 1 Ox App Suite | 2022-08-03 | N/A | 9.8 CRITICAL |
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). | |||||
CVE-2022-29958 | 1 Jtekt | 34 Nano 10gx Tuc-1157, Nano 10gx Tuc-1157 Firmware, Nano Cpu Tuc-6941 and 31 more | 2022-08-03 | N/A | 9.8 CRITICAL |
JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of machine code. The logic that is downloaded to the PLC is not cryptographically authenticated, allowing an attacker to execute arbitrary machine code on the PLC's CPU module in the context of the runtime. In the case of the PC10G-CPU, and likely for other CPU modules of the TOYOPUC family, a processor without MPU or MMU is used and this no memory protection or privilege-separation capabilities are available, giving an attacker full control over the CPU. | |||||
CVE-2022-23099 | 1 Open-xchange | 1 App Suite | 2022-08-03 | N/A | 5.4 MEDIUM |
OX App Suite through 7.10.6 allows XSS by forcing block-wise read. | |||||
CVE-2022-36913 | 1 Jenkins | 1 Openstack Heat | 2022-08-03 | N/A | 4.3 MEDIUM |
Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |||||
CVE-2022-35672 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more | 2022-08-03 | N/A | 7.8 HIGH |
Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-35669 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more | 2022-08-03 | N/A | 5.5 MEDIUM |
Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
CVE-2022-36954 | 1 Veritas | 1 Netbackup | 2022-08-03 | N/A | 6.5 MEDIUM |
In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | |||||
CVE-2022-36955 | 1 Veritas | 1 Netbackup | 2022-08-03 | N/A | 8.4 HIGH |
In Veritas NetBackup, an attacker with unprivileged local access to a NetBackup Client may send specific commands to escalate their privileges. This affects 8.0 through 8.1.2, 8.2, 8.3 through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1. | |||||
CVE-2022-36953 | 1 Veritas | 1 Netbackup | 2022-08-03 | N/A | 4.3 MEDIUM |
In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | |||||
CVE-2022-36952 | 1 Veritas | 1 Netbackup | 2022-08-03 | N/A | 9.8 CRITICAL |
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | |||||
CVE-2022-36951 | 1 Veritas | 1 Netbackup | 2022-08-03 | N/A | 9.8 CRITICAL |
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. |