Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-30297 | 1 Intel | 1 Endpoint Management Assistant | 2022-11-17 | N/A | 7.8 HIGH |
Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2022-44560 | 1 Huawei | 2 Emui, Harmonyos | 2022-11-17 | N/A | 5.3 MEDIUM |
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified. | |||||
CVE-2022-30542 | 1 Intel | 6 R1000wf, R1000wf Firmware, R2000wf and 3 more | 2022-11-17 | N/A | 6.7 MEDIUM |
Improper input validation in the firmware for some Intel(R) Server Board S2600WF, Intel(R) Server System R1000WF and Intel(R) Server System R2000WF families before version R02.01.0014 may allow a privileged user to potentially enable an escalation of privilege via local access. | |||||
CVE-2022-30548 | 1 Intel | 1 Glorp | 2022-11-17 | N/A | 7.8 HIGH |
Uncontrolled search path element in the Intel(R) Glorp software may allow an authenticated user to potentially enable escalation of privilege via local access. | |||||
CVE-2022-3461 | 1 Phoenixcontact | 1 Automationworx Software Suite | 2022-11-17 | N/A | 7.8 HIGH |
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities. | |||||
CVE-2022-30691 | 1 Intel | 1 Support | 2022-11-17 | N/A | 5.5 MEDIUM |
Uncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potentially enable denial of service via local access. | |||||
CVE-2022-33942 | 1 Intel | 1 Data Center Manager | 2022-11-17 | N/A | 8.8 HIGH |
Protection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. | |||||
CVE-2022-42121 | 1 Liferay | 2 Dxp, Liferay Portal | 2022-11-17 | N/A | 8.8 HIGH |
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field. | |||||
CVE-2022-42122 | 1 Liferay | 2 Dxp, Liferay Portal | 2022-11-17 | N/A | 9.8 CRITICAL |
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. | |||||
CVE-2022-4012 | 1 Hospital Management Center Project | 1 Hospital Management Center | 2022-11-17 | N/A | 9.8 CRITICAL |
A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213786 is the identifier assigned to this vulnerability. | |||||
CVE-2022-4013 | 1 Hospital Management Center Project | 1 Hospital Management Center | 2022-11-17 | N/A | 8.8 HIGH |
A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the file appointment.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213787. | |||||
CVE-2022-42111 | 1 Liferay | 2 Dxp, Liferay Portal | 2022-11-17 | N/A | 5.4 MEDIUM |
A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload. | |||||
CVE-2022-26006 | 1 Intel | 260 Core I5-7640x, Core I5-7640x Firmware, Core I7-3820 and 257 more | 2022-11-17 | N/A | 6.7 MEDIUM |
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2022-42120 | 1 Liferay | 2 Dxp, Liferay Portal | 2022-11-17 | N/A | 9.8 CRITICAL |
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. | |||||
CVE-2022-43146 | 1 Canteen Management System Project | 1 Canteen Management System | 2022-11-17 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-42119 | 1 Liferay | 2 Dxp, Liferay Portal | 2022-11-17 | N/A | 5.4 MEDIUM |
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8. | |||||
CVE-2022-36367 | 1 Intel | 1 Support | 2022-11-17 | N/A | 4.4 MEDIUM |
Incorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privileged user to potentially enable information disclosure via local access. | |||||
CVE-2022-42118 | 1 Liferay | 2 Dxp, Liferay Portal | 2022-11-17 | N/A | 6.1 MEDIUM |
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter. | |||||
CVE-2022-34331 | 1 Ibm | 1 Powervm Hypervisor | 2022-11-17 | N/A | 9.8 CRITICAL |
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695. | |||||
CVE-2022-42110 | 1 Liferay | 2 Dxp, Liferay Portal | 2022-11-17 | N/A | 6.1 MEDIUM |
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML. |