Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22450 | LOW | 3.8 | 2022-07-14 | IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. | |
| CVE-2022-2106 | LOW | 3.8 | 2022-06-27 | Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specif… | |
| CVE-2020-16235 | LOW | Patched | 3.8 | 2022-05-19 | Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained. |
| CVE-2022-29423 | LOW | Patched | 3.8 | 2022-05-06 | Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress. |
| CVE-2022-21487 | LOW | Patched | 3.8 | 2022-04-19 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.34. Easily exploitable … |
| CVE-2022-21488 | LOW | Patched | 3.8 | 2022-04-19 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.34. Easily exploitable … |
| CVE-2022-25619 | LOW | Patched | 3.8 | 2022-03-30 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user… |
| CVE-2022-25620 | LOW | Patched | 3.8 | 2022-03-30 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED … |
| CVE-2021-3155 | LOW | Patched | 3.8 | 2022-02-17 | snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read informatio… |
| CVE-2022-24001 | LOW | 3.8 | 2022-02-11 | Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel. | |
| CVE-2022-0473 | LOW | Patched | 3.8 | 2022-02-07 | OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface,… |
| CVE-2021-22799 | LOW | Patched | 3.8 | 2022-01-28 | A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decr… |
| CVE-2022-0333 | LOW | Patched | 3.8 | 2022-01-25 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed manager… |
| CVE-2022-21295 | LOW | Patched | 3.8 | 2022-01-19 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.32. Easily exploitable … |
| CVE-2022-21265 | LOW | Patched | 3.8 | 2022-01-19 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vuln… |
| CVE-2021-25527 | LOW | Patched | 3.8 | 2021-12-08 | Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu wit… |
| CVE-2021-39896 | LOW | Patched | 3.8 | 2021-10-04 | In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonating, the admin may be logged in as the second user t… |
| CVE-2020-25082 | LOW | Patched | 3.8 | 2021-08-10 | An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side… |
| CVE-2021-3595 | LOW | Patched | 3.8 | 2021-06-15 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while process… |
| CVE-2021-3592 | LOW | Patched | 3.8 | 2021-06-15 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while proces… |
| CVE-2021-3593 | LOW | Patched | 3.8 | 2021-06-15 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while process… |
| CVE-2021-3594 | LOW | Patched | 3.8 | 2021-06-15 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processi… |
| CVE-2021-32556 | LOW | Patched | 3.8 | 2021-06-12 | It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the d… |
| CVE-2021-3039 | LOW | Patched | 3.8 | 2021-06-10 | An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authen… |
| CVE-2020-10065 | LOW | Patched | 3.8 | 2021-05-25 | Missing Size Checks in Bluetooth HCI over SPI. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Length Parameter Inconsistency (CWE-130). For more informa… |