Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-27950 | 1 Linux | 1 Linux Kernel | 2022-04-05 | 2.1 LOW | 5.5 MEDIUM |
In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition. | |||||
CVE-2022-0751 | 1 Gitlab | 1 Gitlab | 2022-04-05 | 6.8 MEDIUM | 8.8 HIGH |
Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to create Snippets with misleading content which could trick unsuspecting users into executing arbitrary commands | |||||
CVE-2022-0331 | 1 Sophos | 1 Sfos | 2022-04-05 | 5.0 MEDIUM | 5.3 MEDIUM |
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older. | |||||
CVE-2022-23794 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application. | |||||
CVE-2022-23793 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path. | |||||
CVE-2022-23795 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 6.8 MEDIUM | 9.8 CRITICAL |
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover. | |||||
CVE-2022-23799 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 6.8 MEDIUM | 9.8 CRITICAL |
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data. | |||||
CVE-2022-23797 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection. | |||||
CVE-2022-23798 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 5.8 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not. | |||||
CVE-2022-23800 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components. | |||||
CVE-2022-23796 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields. | |||||
CVE-2022-23801 | 1 Joomla | 1 Joomla\! | 2022-04-05 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media. | |||||
CVE-2022-24135 | 1 Qingscan Project | 1 Qingscan | 2022-04-05 | 4.3 MEDIUM | 6.1 MEDIUM |
QingScan 1.3.0 is affected by Cross Site Scripting (XSS) vulnerability in all search functions. | |||||
CVE-2021-44581 | 1 Kreado | 1 Kreasfero | 2022-04-04 | 5.0 MEDIUM | 7.5 HIGH |
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. | |||||
CVE-2021-45865 | 1 Student Attendance Management System Project | 1 Student Attendance Management System | 2022-04-04 | 7.5 HIGH | 9.8 CRITICAL |
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality. | |||||
CVE-2022-1032 | 1 Craterapp | 1 Crater | 2022-04-04 | 6.5 MEDIUM | 7.2 HIGH |
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | |||||
CVE-2022-26642 | 1 Tp-link | 2 Tl-wr840n, Tl-wr840n Firmware | 2022-04-04 | 6.5 MEDIUM | 7.2 HIGH |
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter. | |||||
CVE-2022-26641 | 1 Tp-link | 2 Tl-wr840n, Tl-wr840n Firmware | 2022-04-04 | 6.5 MEDIUM | 7.2 HIGH |
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter. | |||||
CVE-2020-25180 | 3 Rockwellautomation, Schneider-electric, Xylem | 31 Aadvance Controller, Isagraf Free Runtime, Isagraf Runtime and 28 more | 2022-04-04 | 4.3 MEDIUM | 6.5 MEDIUM |
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device. | |||||
CVE-2020-25178 | 3 Rockwellautomation, Schneider-electric, Xylem | 31 Aadvance Controller, Isagraf Free Runtime, Isagraf Runtime and 28 more | 2022-04-04 | 9.3 HIGH | 8.8 HIGH |
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files. |