Search Results (35019 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-23928 1 Hp 1 Pc Bios 2024-11-21 8.2 High
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.
CVE-2022-23927 1 Hp 1 Pc Bios 2024-11-21 8.2 High
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.
CVE-2022-23926 1 Hp 1 Pc Bios 2024-11-21 8.2 High
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.
CVE-2022-23925 1 Hp 1 Pc Bios 2024-11-21 8.2 High
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.
CVE-2022-23924 1 Hp 1 Pc Bios 2024-11-21 8.2 High
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.
CVE-2022-23923 1 Jailed Project 1 Jailed 2024-11-21 8.6 High
All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.
CVE-2022-23878 1 Seacms 1 Seacms 2024-11-21 9.8 Critical
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
CVE-2022-23863 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 6.5 Medium
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
CVE-2022-23858 1 Starwindsoftware 1 Command Center 2024-11-21 8.8 High
A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Center build 6003 v2.
CVE-2022-23849 1 Devolutions 1 Password Hub 2024-11-21 6.6 Medium
The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.
CVE-2022-23848 1 Alluxio 1 Alluxio 2024-11-21 9.8 Critical
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
CVE-2022-23830 1 Amd 130 Epyc 7203, Epyc 7203 Firmware, Epyc 7203p and 127 more 2024-11-21 1.9 Low
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
CVE-2022-23774 2 Docker, Microsoft 2 Docker Desktop, Windows 2024-11-21 5.3 Medium
Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
CVE-2022-23744 1 Checkpoint 2 Endpoint Security, Harmony Endpoint 2024-11-21 2.3 Low
Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.
CVE-2022-23731 1 Lg 1 Webos 2024-11-21 7.8 High
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
CVE-2022-23728 1 Google 1 Android 2024-11-21 6.1 Medium
Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.
CVE-2022-23727 1 Lg 1 Webos 2024-11-21 7.8 High
There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege
CVE-2022-23714 2 Elastic, Microsoft 2 Endpoint Security, Windows 2024-11-21 7.8 High
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.
CVE-2022-23712 1 Elastic 1 Elasticsearch 2024-11-21 7.5 High
A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.
CVE-2022-23711 1 Elastic 1 Kibana 2024-11-21 5.3 Medium
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.