Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-45861 1 Tsmuxer Project 1 Tsmuxer 2022-03-09 4.3 MEDIUM 5.5 MEDIUM
There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.
CVE-2021-45860 1 Tsmuxer Project 1 Tsmuxer 2022-03-09 4.3 MEDIUM 5.5 MEDIUM
An integer overflow in DTSStreamReader::findFrame() of tsMuxer git-2678966 allows attackers to cause a Denial of Service (DoS) via a crafted file.
CVE-2022-25012 1 Argussurveillance 1 Dvr 2022-03-09 2.1 LOW 5.5 MEDIUM
Argus Surveillance DVR v4.0 employs weak password encryption.
CVE-2022-25010 1 Stepmania 1 Stepmania 2022-03-09 6.4 MEDIUM 9.1 CRITICAL
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
CVE-2022-23640 1 Excel Streaming Reader Project 1 Excel Streaming Reader 2022-03-09 7.5 HIGH 9.8 CRITICAL
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a patch. There is no known workaround.
CVE-2022-23878 1 Seacms 1 Seacms 2022-03-09 7.5 HIGH 9.8 CRITICAL
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
CVE-2021-46270 1 Jfrog 1 Artifactory 2022-03-09 4.0 MEDIUM 2.7 LOW
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
CVE-2022-25809 1 Amazon 2 Echo Dot, Echo Dot Firmware 2022-03-09 9.0 HIGH 9.8 CRITICAL
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.
CVE-2022-25016 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2022-03-09 7.5 HIGH 9.8 CRITICAL
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-24255 1 Extensis 1 Portfolio 2022-03-09 9.0 HIGH 8.8 HIGH
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
CVE-2022-22350 1 Ibm 2 Aix, Vios 2022-03-09 2.1 LOW 5.5 MEDIUM
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.
CVE-2021-43070 1 Fortinet 1 Fortiwlm 2022-03-09 4.0 MEDIUM 6.5 MEDIUM
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
CVE-2022-24254 1 Extensis 1 Portfolio 2022-03-09 6.5 MEDIUM 8.8 HIGH
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.
CVE-2022-24253 1 Extensis 1 Portfolio 2022-03-09 6.5 MEDIUM 8.8 HIGH
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
CVE-2022-24252 1 Extensis 1 Portfolio 2022-03-09 6.5 MEDIUM 8.8 HIGH
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.
CVE-2022-24251 1 Extensis 1 Portfolio 2022-03-09 6.5 MEDIUM 8.8 HIGH
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
CVE-2021-41652 1 Batflat 1 Batflat 2022-03-09 5.0 MEDIUM 7.5 HIGH
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
CVE-2021-38996 1 Ibm 2 Aix, Vios 2022-03-09 2.1 LOW 5.5 MEDIUM
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213076.
CVE-2021-39363 1 Honeywell 4 Hbw2per1, Hbw2per1 Firmware, Hdzp252di and 1 more 2022-03-09 7.5 HIGH 9.8 CRITICAL
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.
CVE-2021-39364 1 Honeywell 4 Hbw2per1, Hbw2per1 Firmware, Hdzp252di and 1 more 2022-03-09 5.0 MEDIUM 7.5 HIGH
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.