Search Results (328201 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-2831 1 Blender 1 Blender 2024-11-21 7.5 High
A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.
CVE-2022-2830 1 Bitdefender 1 Gravityzone 2024-11-21 8.8 High
Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console allows an attacker to pass unsafe commands to the environment. This issue affects: Bitdefender GravityZone Console On-Premise versions prior to 6.29.2-1. Bitdefender GravityZone Cloud Console versions prior to 6.27.2-2.
CVE-2022-2829 1 Yetiforce 1 Yetiforce Customer Relationship Management 2024-11-21 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-2824 1 Open-emr 1 Openemr 2024-11-21 8.8 High
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2823 1 Metaslider 1 Slider\, Gallery\, And Carousel 2024-11-21 4.8 Medium
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its Gallery Image parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-2822 1 Octoprint 1 Octoprint 2024-11-21 7.5 High
An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.
CVE-2022-2821 1 Namelessmc 1 Nameless 2024-11-21 7.5 High
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
CVE-2022-2820 1 Namelessmc 1 Nameless 2024-11-21 7 High
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
CVE-2022-2819 2 Fedoraproject, Vim 2 Fedora, Vim 2024-11-21 7.8 High
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
CVE-2022-2818 1 Agentejo 1 Cockpit 2024-11-21 9.8 Critical
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
CVE-2022-2817 2 Fedoraproject, Vim 2 Fedora, Vim 2024-11-21 7.8 High
Use After Free in GitHub repository vim/vim prior to 9.0.0213.
CVE-2022-2816 2 Fedoraproject, Vim 2 Fedora, Vim 2024-11-21 7.8 High
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
CVE-2022-2808 1 Algan 1 Prens Student Information System 2024-11-21 8.8 High
Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection.This issue affects Prens Student Information System: before 2.1.11.
CVE-2022-2806 3 Ovirt, Redhat, Sos Project 3 Log Collector, Rhev Manager, Sos 2024-11-21 5.5 Medium
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
CVE-2022-2799 1 Wpaffiliatemanager 1 Affiliates Manager 2024-11-21 4.8 Medium
The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-2798 1 Wpaffiliatemanager 1 Affiliates Manager 2024-11-21 8.0 High
The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could allow users registering as affiliate to perform CSV injection attacks against an admin exporting the data
CVE-2022-2796 1 Pimcore 1 Pimcore 2024-11-21 4.8 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.4.
CVE-2022-2787 1 Debian 2 Debian Linux, Schroot 2024-11-21 4.3 Medium
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
CVE-2022-2783 1 Octopus 1 Octopus Server 2024-11-21 5.3 Medium
In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token
CVE-2022-2781 1 Octopus 1 Octopus Server 2024-11-21 5.3 Medium
In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.