Search Results (324414 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-32844 1 Ivanti 2 Endpoint Manager, Epm 2025-04-23 7.2 High
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2022-3710 1 Sophos 2 Xg Firewall, Xg Firewall Firmware 2025-04-23 2.7 Low
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
CVE-2022-23143 1 Zte 2 Otcp, Otcp Firmware 2025-04-23 6.5 Medium
ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.
CVE-2022-43900 1 Ibm 1 Websphere Automation For Ibm Cloud Pak For Watson Aiops 2025-04-23 5.3 Medium
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827.
CVE-2022-45478 1 Telepad-app 1 Telepad 2025-04-23 5.1 Medium
Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2022-42864 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2025-04-23 7 High
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
CVE-2022-42774 2 Google, Unisoc 14 Android, S8002, Sc7731e and 11 more 2025-04-23 5.5 Medium
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42773 2 Google, Unisoc 14 Android, S8001, Sc7731e and 11 more 2025-04-23 5.5 Medium
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42772 2 Google, Unisoc 14 Android, S8021, Sc7731e and 11 more 2025-04-23 5.5 Medium
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42771 2 Google, Unisoc 14 Android, S8020, Sc7731e and 11 more 2025-04-23 4.7 Medium
In wlan driver, there is a race condition, This could lead to local denial of service in wlan services.
CVE-2022-42768 2 Google, Unisoc 14 Android, S8013, Sc7731e and 11 more 2025-04-23 4.3 Medium
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42767 2 Google, Unisoc 14 Android, S8012, Sc7731e and 11 more 2025-04-23 6.6 Medium
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42766 2 Google, Unisoc 14 Android, S8011, Sc7731e and 11 more 2025-04-23 6.6 Medium
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
CVE-2022-42765 2 Google, Unisoc 15 Android, S8000, S8010 and 12 more 2025-04-23 6.6 Medium
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42756 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-04-23 7.7 High
In sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-42754 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-04-23 5.5 Medium
In npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.
CVE-2022-41325 2 Debian, Videolan 2 Debian Linux, Vlc Media Player 2025-04-23 7.8 High
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
CVE-2022-20521 1 Google 1 Android 2025-04-23 5 Medium
In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227203684
CVE-2021-42383 2 Busybox, Fedoraproject 2 Busybox, Fedora 2025-04-23 7.2 High
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
CVE-2021-42375 3 Busybox, Fedoraproject, Netapp 19 Busybox, Fedora, Cloud Backup and 16 more 2025-04-23 5.5 Medium
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.