CVE Vulnerability Database

Search and browse 61 known security vulnerabilities. Filter by severity, vendor, product, and year.

61 vulnerabilities found
CVE-2022-3775
7.1 high

When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and a

Gnu Grub2 Dec 19, 2022
CVE-2022-2601
8.6 high

A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker

Gnu Grub2 Dec 14, 2022
CVE-2022-44702
7.8 high

Windows Terminal Remote Code Execution Vulnerability

Microsoft Terminal Dec 13, 2022
CVE-2022-44696
7.8 high

Microsoft Office Visio Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 13, 2022
CVE-2022-44695
7.8 high

Microsoft Office Visio Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 13, 2022
CVE-2022-44694
7.8 high

Microsoft Office Visio Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 13, 2022
CVE-2022-3907
7.5 high

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

Clerk.Io Clerk.Io Dec 5, 2022
CVE-2022-2808
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects Prens Student Information System: before 2.1.11.

Algan Prens Student Information System Dec 2, 2022
CVE-2022-46152
8.2 high

OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_refs()` is called by both `entry_invoke_command()` and `entry_open_session()`. The

Trustedfirmware Op-Tee Nov 29, 2022
CVE-2022-24037
8.2 high

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information.

Karmasis Infraskope Siem\+ Nov 18, 2022
CVE-2022-24036
8.6 high

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.

Karmasis Infraskope Siem\+ Nov 16, 2022
CVE-2022-41107
7.8 high

Microsoft Office Graphics Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41106
8.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41063
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41061
7.8 high

Microsoft Word Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-40227
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMAT

Siemens Simatic Hmi Comfort Panels Firmware Oct 11, 2022
CVE-2022-20920
7.7 high

A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this v

Cisco Ios Oct 10, 2022
CVE-2022-2265
7.5 high

The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25

Identity And Directory Management System Project Identity And Directory Management System Sep 21, 2022
CVE-2022-38013
7.5 high

.NET Core and Visual Studio Denial of Service Vulnerability

Microsoft .Net Sep 13, 2022
CVE-2022-34169
7.5 high

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or l

Apache Xalan-Java Jul 19, 2022
CVE-2022-34151
8.1 high

Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation software 'Sysmac Studi

Omron Nx701-1600 Firmware Jul 4, 2022
CVE-2022-33971
7.5 high

Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an

Omron Nx701-1600 Firmware Jul 4, 2022
CVE-2022-24946
7.5 high

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the fir

Mitsubishielectric Q03Udecpu Firmware Jun 15, 2022
CVE-2022-27782
7.5 high

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH se

Haxx Curl Jun 2, 2022