CVE Vulnerability Database

Search and browse 111 known security vulnerabilities. Filter by severity, vendor, product, and year.

111 vulnerabilities found
CVE-2022-39399
3.7 low

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability

Oracle Graalvm Oct 18, 2022
CVE-2022-21626
5.3 medium

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerabilit

Oracle Graalvm Oct 18, 2022
CVE-2022-21624
3.7 low

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit

Oracle Graalvm Oct 18, 2022
CVE-2022-21619
3.7 low

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to expl

Oracle Graalvm Oct 18, 2022
CVE-2022-21618
5.3 medium

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated att

Oracle Graalvm Oct 18, 2022
CVE-2022-40227
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMAT

Siemens Simatic Hmi Comfort Panels Firmware Oct 11, 2022
CVE-2022-20920
7.7 high

A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this v

Cisco Ios Oct 10, 2022
CVE-2022-2266
6.1 medium

University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the version 19.2

Yordam Library Automation System Sep 22, 2022
CVE-2022-2265
7.5 high

The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25

Identity And Directory Management System Project Identity And Directory Management System Sep 21, 2022
CVE-2022-0495
9.4 critical

The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.

Parantezteknoloji Koha Library Automation Sep 21, 2022
CVE-2022-2315
9.4 critical

Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.

Databank Accreditation Tracking\/Presentation Module Sep 21, 2022
CVE-2022-2177
9.4 critical

Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.

Kayrasoft Kayrasoft Sep 20, 2022
CVE-2022-38013
7.5 high

.NET Core and Visual Studio Denial of Service Vulnerability

Microsoft .Net Sep 13, 2022
CVE-2022-28880
4.3 medium

A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker.

F-Secure Elements Endpoint Detection And Response Aug 5, 2022
CVE-2022-1277
9.4 critical

Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.

Inavitas Solar Log Jul 29, 2022
CVE-2021-41556
10.0 critical

sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dange

Squirrel-Lang Squirrel Jul 28, 2022
CVE-2022-2160
6.5 medium

Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.

Google Chrome Jul 28, 2022
CVE-2022-21549
5.3 medium

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated at

Oracle Graalvm Jul 19, 2022
CVE-2022-21540
5.3 medium

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitabl

Oracle Graalvm Jul 19, 2022
CVE-2022-34169
7.5 high

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or l

Apache Xalan-Java Jul 19, 2022
CVE-2022-35409
9.1 critical

An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information dis

Arm Mbed Tls Jul 15, 2022
CVE-2022-34151
8.1 high

Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studi

Omron Nx701-1600 Firmware Jul 4, 2022
CVE-2022-33971
7.5 high

Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an

Omron Nx701-1600 Firmware Jul 4, 2022
CVE-2022-24946
7.5 high

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the fir

Mitsubishielectric Q03Udecpu Firmware Jun 15, 2022