Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-45861 | 1 Tsmuxer Project | 1 Tsmuxer | 2022-03-09 | 4.3 MEDIUM | 5.5 MEDIUM |
There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277. | |||||
CVE-2021-45860 | 1 Tsmuxer Project | 1 Tsmuxer | 2022-03-09 | 4.3 MEDIUM | 5.5 MEDIUM |
An integer overflow in DTSStreamReader::findFrame() of tsMuxer git-2678966 allows attackers to cause a Denial of Service (DoS) via a crafted file. | |||||
CVE-2022-25012 | 1 Argussurveillance | 1 Dvr | 2022-03-09 | 2.1 LOW | 5.5 MEDIUM |
Argus Surveillance DVR v4.0 employs weak password encryption. | |||||
CVE-2022-25010 | 1 Stepmania | 1 Stepmania | 2022-03-09 | 6.4 MEDIUM | 9.1 CRITICAL |
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system. | |||||
CVE-2022-23640 | 1 Excel Streaming Reader Project | 1 Excel Streaming Reader | 2022-03-09 | 7.5 HIGH | 9.8 CRITICAL |
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a patch. There is no known workaround. | |||||
CVE-2022-23878 | 1 Seacms | 1 Seacms | 2022-03-09 | 7.5 HIGH | 9.8 CRITICAL |
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | |||||
CVE-2021-46270 | 1 Jfrog | 1 Artifactory | 2022-03-09 | 4.0 MEDIUM | 2.7 LOW |
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation. | |||||
CVE-2022-25809 | 1 Amazon | 2 Echo Dot, Echo Dot Firmware | 2022-03-09 | 9.0 HIGH | 9.8 CRITICAL |
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack. | |||||
CVE-2022-25016 | 1 Home Owners Collection Management System Project | 1 Home Owners Collection Management System | 2022-03-09 | 7.5 HIGH | 9.8 CRITICAL |
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-24255 | 1 Extensis | 1 Portfolio | 2022-03-09 | 9.0 HIGH | 8.8 HIGH |
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges. | |||||
CVE-2022-22350 | 1 Ibm | 2 Aix, Vios | 2022-03-09 | 2.1 LOW | 5.5 MEDIUM |
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394. | |||||
CVE-2021-43070 | 1 Fortinet | 1 Fortiwlm | 2022-03-09 | 4.0 MEDIUM | 6.5 MEDIUM |
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests. | |||||
CVE-2022-24254 | 1 Extensis | 1 Portfolio | 2022-03-09 | 6.5 MEDIUM | 8.8 HIGH |
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file. | |||||
CVE-2022-24253 | 1 Extensis | 1 Portfolio | 2022-03-09 | 6.5 MEDIUM | 8.8 HIGH |
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet. | |||||
CVE-2022-24252 | 1 Extensis | 1 Portfolio | 2022-03-09 | 6.5 MEDIUM | 8.8 HIGH |
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file. | |||||
CVE-2022-24251 | 1 Extensis | 1 Portfolio | 2022-03-09 | 6.5 MEDIUM | 8.8 HIGH |
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function. | |||||
CVE-2021-41652 | 1 Batflat | 1 Batflat | 2022-03-09 | 5.0 MEDIUM | 7.5 HIGH |
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database. | |||||
CVE-2021-38996 | 1 Ibm | 2 Aix, Vios | 2022-03-09 | 2.1 LOW | 5.5 MEDIUM |
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213076. | |||||
CVE-2021-39363 | 1 Honeywell | 4 Hbw2per1, Hbw2per1 Firmware, Hdzp252di and 1 more | 2022-03-09 | 7.5 HIGH | 9.8 CRITICAL |
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved. | |||||
CVE-2021-39364 | 1 Honeywell | 4 Hbw2per1, Hbw2per1 Firmware, Hdzp252di and 1 more | 2022-03-09 | 5.0 MEDIUM | 7.5 HIGH |
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved. |