Export limit exceeded: 35128 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (35128 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-31594 1 Sap 1 Adaptive Server Enterprise 2024-11-21 6.7 Medium
A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.
CVE-2022-31590 1 Sap 1 Powerdesigner Proxy 2024-11-21 7.8 High
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.
CVE-2022-31478 1 Sr.solutions 1 Usertakeover 2024-11-21 4.3 Medium
The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.
CVE-2022-31472 1 Cybozu 1 Garoon 2024-11-21 4.3 Medium
Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to obtain the data of Cabinet.
CVE-2022-31313 1 Api-res-py Project 1 Api-res-py 2024-11-21 9.8 Critical
api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package.
CVE-2022-31282 1 Axiosys 1 Bento4 2024-11-21 5.5 Medium
Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.
CVE-2022-31263 1 Joinmastodon 1 Mastodon 2024-11-21 5.3 Medium
app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
CVE-2022-31259 1 Beego 1 Beego 2024-11-21 9.8 Critical
The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).
CVE-2022-31208 1 Infiray 2 Iray-a8z3, Iray-a8z3 Firmware 2024-11-21 8.8 High
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the cmd_string URL parameter.
CVE-2022-30949 1 Jenkins 1 Repo 2024-11-21 5.3 Medium
Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
CVE-2022-30948 2 Jenkins, Redhat 2 Mercurial, Openshift 2024-11-21 7.5 High
Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
CVE-2022-30947 1 Jenkins 1 Git 2024-11-21 7.5 High
Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.
CVE-2022-30943 1 Cybozu 1 Garoon 2024-11-21 4.3 Medium
Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data of Bulletin.
CVE-2022-30882 1 Pyanxdns Project 1 Pyanxdns 2024-11-21 9.8 Critical
pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed.
CVE-2022-30785 3 Debian, Fedoraproject, Tuxera 3 Debian Linux, Fedora, Ntfs-3g 2024-11-21 6.7 Medium
A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
CVE-2022-30756 1 Google 1 Android 2024-11-21 8.5 High
Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.
CVE-2022-30754 1 Google 1 Android 2024-11-21 8.5 High
Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.
CVE-2022-30737 1 Samsung 1 Account 2024-11-21 4 Medium
Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.
CVE-2022-30726 1 Google 1 Android 2024-11-21 6.2 Medium
Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.
CVE-2022-30722 1 Google 1 Android 2024-11-21 6.2 Medium
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.