Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26624 1 Escanav 1 Escan Anti-virus 2022-04-08 10.0 HIGH 8.8 HIGH
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root privileges by manipulating parameter values.
CVE-2021-23287 1 Eaton 1 Intelligent Power Manager 2022-04-08 3.5 LOW 5.4 MEDIUM
The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70.
CVE-2021-23288 1 Eaton 1 Intelligent Power Protector 2022-04-08 2.3 LOW 4.8 MEDIUM
The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. This issue affects: Intelligent Power Protector versions prior to 1.69.
CVE-2021-23247 1 Oppo 1 Quick App 2022-04-08 7.5 HIGH 9.8 CRITICAL
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine
CVE-2020-14479 1 Inductiveautomation 1 Ignition 2022-04-08 5.0 MEDIUM 5.3 MEDIUM
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
CVE-2019-14839 1 Redhat 3 Business-central, Descision Manager, Process Automation 2022-04-08 5.0 MEDIUM 7.5 HIGH
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
CVE-2022-24066 1 Simple-git Project 1 Simple-git 2022-04-08 7.5 HIGH 9.8 CRITICAL
The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover.
CVE-2022-23155 1 Dell 1 Wyse Management Suite 2022-04-08 9.0 HIGH 7.2 HIGH
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.
CVE-2022-25017 1 Hitrontech 2 Chita, Chita Firmware 2022-04-08 9.0 HIGH 8.8 HIGH
Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.
CVE-2021-35117 1 Qualcomm 204 Apq8096au, Apq8096au Firmware, Aqt1000 and 201 more 2022-04-08 9.4 HIGH 9.1 CRITICAL
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
CVE-2021-35115 1 Qualcomm 56 Apq8096au, Apq8096au Firmware, Ar6003 and 53 more 2022-04-08 4.6 MEDIUM 7.8 HIGH
Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile
CVE-2021-35110 1 Qualcomm 12 Sd 8 Gen1 5g, Sd 8 Gen1 5g Firmware, Wcd9380 and 9 more 2022-04-08 7.2 HIGH 8.8 HIGH
Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivity, Snapdragon Mobile
CVE-2021-35106 1 Qualcomm 224 Aqt1000, Aqt1000 Firmware, Ar8031 and 221 more 2022-04-08 7.2 HIGH 7.8 HIGH
Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVE-2021-35105 1 Qualcomm 314 Apq8009w, Apq8009w Firmware, Apq8017 and 311 more 2022-04-08 7.2 HIGH 7.8 HIGH
Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVE-2021-35103 1 Qualcomm 298 Ar8035, Ar8035 Firmware, Ar9380 and 295 more 2022-04-08 7.2 HIGH 7.8 HIGH
Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
CVE-2017-5130 3 Debian, Google, Xmlsoft 3 Debian Linux, Chrome, Libxml2 2022-04-08 6.8 MEDIUM 8.8 HIGH
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.
CVE-2017-16932 1 Xmlsoft 1 Libxml2 2022-04-08 5.0 MEDIUM 7.5 HIGH
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
CVE-2017-5969 1 Xmlsoft 1 Libxml2 2022-04-08 2.6 LOW 4.7 MEDIUM
** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser."
CVE-2016-9318 3 Canonical, Xmlsec Project, Xmlsoft 3 Ubuntu Linux, Xmlsec, Libxml2 2022-04-08 4.3 MEDIUM 5.5 MEDIUM
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
CVE-2021-43149 2022-04-08 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.