Search Results (80659 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-38992 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38991 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38990 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38989 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38988 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38987 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-38979 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38978 1 Huawei 3 Emui, Harmonyos, Magic Ui 2024-11-21 7.5 High
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-38862 1 Mplayerhq 2 Mencoder, Mplayer 2024-11-21 7.8 High
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function play() of libaf/af.c:639. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
CVE-2022-38844 1 Espocrm 1 Espocrm 2024-11-21 8.0 High
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.
CVE-2022-38843 1 Espocrm 1 Espocrm 2024-11-21 8.8 High
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.
CVE-2022-38817 1 Linuxfoundation 1 Dapr Dashboard 2024-11-21 7.5 High
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
CVE-2022-38808 1 Yimihome 1 Ywoa 2024-11-21 8.8 High
ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
CVE-2022-38794 1 Zaver Project 1 Zaver 2024-11-21 7.5 High
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
CVE-2022-38784 4 Debian, Fedoraproject, Freedesktop and 1 more 4 Debian Linux, Fedora, Poppler and 1 more 2024-11-21 7.8 High
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
CVE-2022-38772 1 Zohocorp 6 Manageengine Netflow Analyzer, Manageengine Network Configuration Manager, Manageengine Opmanager and 3 more 2024-11-21 8.8 High
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
CVE-2022-38769 1 Transtek 1 Mojodat Fixed Asset Management 2024-11-21 7.5 High
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext passwords upon a successful login request.
CVE-2022-38764 2 Microsoft, Trendmicro 2 Windows, Housecall 2024-11-21 7.8 High
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissive folder om the product installer.
CVE-2022-38715 1 Siretta 2 Quartz-gold, Quartz-gold Firmware 2024-11-21 8.8 High
A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-38700 1 Openharmony 1 Openharmony 2024-11-21 8.8 High
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.