CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2022-27879

    Last Modified: 13 Feb 2025

    Improper buffer restrictions in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2022-38083

    Last Modified: 13 Feb 2025

    Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

    Published: 11 Aug 2023
    6.9
    Medium

    CVE-2022-44611

    Last Modified: 13 Feb 2025

    Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.

    Published: 11 Aug 2023
    7.2
    High

    CVE-2022-37343

    Last Modified: 13 Feb 2025

    Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    3.3
    Low

    CVE-2022-38973

    Last Modified: 21 Nov 2024

    Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow an authenticated user to potentially enable denial of service or infomation disclosure via local access.

    Published: 11 Aug 2023
    4.4
    Medium

    CVE-2022-41984

    Last Modified: 21 Nov 2024

    Protection mechanism failure for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow a privileged user to potentially enable denial of service via local access.

    Published: 11 Aug 2023
    6.7
    Medium

    CVE-2023-24016

    Last Modified: 21 Nov 2024

    Uncontrolled search path element in some Intel(R) Quartus(R) Prime Pro and Standard edition software for linux may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    6.7
    Medium

    CVE-2022-43456

    Last Modified: 21 Nov 2024

    Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    6.7
    Medium

    CVE-2022-29871

    Last Modified: 13 Feb 2025

    Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Aug 2023
    7.2
    High

    CVE-2022-38102

    Last Modified: 13 Feb 2025

    Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access.

    Published: 11 Aug 2023
    8.6
    High

    CVE-2022-36392

    Last Modified: 13 Feb 2025

    Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, and 16.1.27 in Intel (R) CSME may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 11 Aug 2023
    6
    Medium

    CVE-2022-34657

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for some Intel(R) PCSD BIOS before version 02.01.0013 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 11 Aug 2023
    3.3
    Low

    CVE-2023-37512

    Last Modified: 21 Nov 2024

    When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.

    Published: 11 Aug 2023
    3.3
    Low

    CVE-2023-37513

    Last Modified: 21 Nov 2024

    When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information.

    Published: 11 Aug 2023
    3.5
    Low

    CVE-2023-37511

    Last Modified: 21 Nov 2024

    If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.

    Published: 11 Aug 2023
    3.8
    Low

    CVE-2023-4304

    Last Modified: 21 Nov 2024

    Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

    Published: 11 Aug 2023
    9.8
    Critical

    CVE-2023-40256

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and integrity of messages controlling the backup and restore jobs, and could result in the service becoming unavailable. This impacts only the jobs controlling the backup and restore activities, and does not allow access to (or deletion of) the backup snapshot data itself. This vulnerability is confined to the NetBackup Snapshot Manager feature and does not impact the RabbitMQ instance on the NetBackup primary servers.

    Published: 11 Aug 2023
    7.8
    High

    CVE-2023-22955

    Last Modified: 17 Apr 2025

    An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.

    Published: 11 Aug 2023
    6.5
    Medium

    CVE-2020-24904

    Last Modified: 21 Nov 2024

    An issue was discovered in attach parameter in GNOME Gmail version 2.5.4, allows remote attackers to gain sensitive information via crafted "mailto" link.

    Published: 11 Aug 2023
    5.4
    Medium

    CVE-2020-25915

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.

    Published: 11 Aug 2023
    9.1
    Critical

    CVE-2020-27514

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2020-28717

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.

    Published: 11 Aug 2023
    7.8
    High

    CVE-2020-28840

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).

    Published: 11 Aug 2023
    8.8
    High

    CVE-2020-28848

    Last Modified: 21 Nov 2024

    CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.

    Published: 11 Aug 2023
    5.5
    Medium

    CVE-2020-35990

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2020-36138

    Last Modified: 21 Nov 2024

    An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).

    Published: 11 Aug 2023
    7.5
    High

    CVE-2021-26504

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2023-22956

    Last Modified: 21 Nov 2024

    An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.

    Published: 11 Aug 2023
    7.5
    High

    CVE-2023-22957

    Last Modified: 21 Nov 2024

    An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.

    Published: 11 Aug 2023
    9.8
    Critical

    CVE-2021-28411

    Last Modified: 21 Nov 2024

    An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.

    Published: 11 Aug 2023
    7.8
    High

    CVE-2021-28835

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.

    Published: 11 Aug 2023
    5.3
    Medium

    CVE-2021-25786

    Last Modified: 21 Nov 2024

    An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.

    Published: 11 Aug 2023
    4.9
    Medium

    CVE-2021-25856

    Last Modified: 21 Nov 2024

    An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php.

    Published: 11 Aug 2023
    7.2
    High

    CVE-2021-25857

    Last Modified: 21 Nov 2024

    An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.

    Published: 11 Aug 2023
    9.8
    Critical

    CVE-2021-26505

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.

    Published: 11 Aug 2023
    9.8
    Critical

    CVE-2021-27523

    Last Modified: 21 Nov 2024

    An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface.

    Published: 11 Aug 2023
    7.8
    High

    CVE-2021-28427

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.

    Published: 11 Aug 2023
    5.5
    Medium

    CVE-2021-28429

    Last Modified: 21 Nov 2024

    Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.

    Published: 11 Aug 2023
    6.5
    Medium

    CVE-2021-29057

    Last Modified: 21 Nov 2024

    An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.

    Published: 11 Aug 2023
    8.8
    High

    CVE-2021-29378

    Last Modified: 21 Nov 2024

    SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2020-19952

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file.

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2020-20523

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to execute arbitrary code during the Gila CMS installation.

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2020-24075

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers to execute arbitrary code.

    Published: 11 Aug 2023
    5.5
    Medium

    CVE-2020-24187

    Last Modified: 21 Nov 2024

    An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference).

    Published: 11 Aug 2023
    5.5
    Medium

    CVE-2020-24221

    Last Modified: 21 Nov 2024

    An issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of service (DoS) via crafted .gif file (infinite loop).

    Published: 11 Aug 2023
    6.5
    Medium

    CVE-2020-24804

    Last Modified: 21 Nov 2024

    Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs.

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2020-24872

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.

    Published: 11 Aug 2023
    8.8
    High

    CVE-2020-24922

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.

    Published: 11 Aug 2023
    8.8
    High

    CVE-2020-24950

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.

    Published: 11 Aug 2023
    6.1
    Medium

    CVE-2020-27449

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.

    Published: 11 Aug 2023