Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2023-23910 LOW Patched 3.9 2023-05-10 Out-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escala…
CVE-2021-46762 LOW 3.9 2023-05-09 Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
CVE-2023-30624 LOW Patched 3.9 2023-04-27 Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation of managing per-instance state, such as tables and me…
CVE-2023-30544 LOW Patched 3.9 2023-04-24 Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page.…
CVE-2022-1230 LOW Patched 3.9 2023-03-28 This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain …
CVE-2023-22591 LOW Patched 3.9 2023-03-15 IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being inv…
CVE-2023-23939 LOW Patched 3.9 2023-03-06 Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows ot…
CVE-2023-0808 LOW 3.9 2023-02-13 A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processin…
CVE-2022-34376 LOW Patched 3.9 2023-02-10 Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnera…
CVE-2022-3083 LOW 3.9 2023-02-01 All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity. The device's web application navigation depends on…
CVE-2022-22732 LOW Patched 3.9 2023-01-30 A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attac…
CVE-2022-46827 LOW Patched 3.9 2022-12-08 In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVE-2022-39910 LOW Patched 3.9 2022-12-08 Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked de…
CVE-2022-39334 LOW Patched 3.9 2022-11-25 Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would i…
CVE-2022-30307 LOW Patched 3.9 2022-11-02 A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated atta…
CVE-2022-39403 LOW Patched 3.9 2022-10-18 Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vuln…
CVE-2022-36851 LOW Patched 3.9 2022-09-09 Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
CVE-2022-1697 LOW 3.9 2022-09-06 Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must…
CVE-2022-2788 LOW Patched 3.9 2022-08-19 Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload …
CVE-2021-27785 LOW Patched 3.9 2022-07-30 HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particula…
CVE-2022-37009 LOW Patched 3.9 2022-07-28 In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
CVE-2022-20226 LOW 3.9 2022-07-13 In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with …
CVE-2022-0997 LOW Patched 3.9 2022-05-17 Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the…
CVE-2022-29817 LOW Patched 3.9 2022-04-28 In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
CVE-2022-29818 LOW Patched 3.9 2022-04-28 In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed