1915 items
Unread (2164) All Dismissed
CRITICAL
CVE-2022-35409 (CVSS 9.1) — An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an u...
NVD CVE-2022-35409 1423d ago
HIGH
CVE-2022-34151 (CVSS 8.1) — Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all mo...
NVD CVE-2022-34151 1434d ago
HIGH
CVE-2022-33971 (CVSS 7.5) — Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 se...
NVD CVE-2022-33971 1434d ago
HIGH
CVE-2022-24946 (CVSS 7.5) — Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware...
NVD CVE-2022-24946 1452d ago
HIGH
CVE-2022-27782 (CVSS 7.5) — libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been ch...
NVD CVE-2022-27782 1466d ago
HIGH
CVE-2022-27781 (CVSS 7.5) — libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returne...
NVD CVE-2022-27781 1466d ago
HIGH
CVE-2022-27775 (CVSS 7.5) — An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using...
NVD CVE-2022-27775 1466d ago
HIGH
CVE-2022-22576 (CVSS 8.1) — An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might a...
NVD CVE-2022-22576 1472d ago
HIGH
CVE-2022-22977 (CVSS 7.1) — VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerabil...
NVD CVE-2022-22977 1474d ago
HIGH
CVE-2022-23742 (CVSS 7.8) — Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensi...
NVD CVE-2022-23742CVE-2020-0896 1486d ago
HIGH
CVE-2022-27224 (CVSS 7.2) — An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated at...
NVD CVE-2022-27224 1490d ago
HIGH
CVE-2022-25647 (CVSS 7.7) — The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Da...
NVD CVE-2022-25647 1497d ago
HIGH
CVE-2022-0354 (CVSS 7.3) — A vulnerability was reported in Lenovo System Update that could allow a local user with interactive ...
NVD CVE-2022-0354 1506d ago
HIGH
CVE-2022-0778 (CVSS 7.5) — The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it t...
NVD CVE-2022-0778 1544d ago
CRITICAL
CVE-2022-0715 (CVSS 9.1) — A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily ...
NVD CVE-2022-0715 1550d ago
CRITICAL
CVE-2022-0492: Linux Kernel Improper Authentication Vulnerability (Linux Kernel)
CISA KEV CVE-2022-0492actively-exploited +1 5d ago
HIGH
CVE-2022-0492 (CVSS 7.8) — A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgro...
NVD 1556d ago
HIGH
CVE-2021-43619 (CVSS 7.8) — Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition....
NVD CVE-2021-43619 1559d ago
HIGH
CVE-2021-22788 (CVSS 7.5) — A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attac...
NVD CVE-2021-22788 1576d ago
HIGH
CVE-2021-22787 (CVSS 7.5) — A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the d...
NVD CVE-2021-22787 1576d ago
HIGH
CVE-2021-22785 (CVSS 7.5) — A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files...
NVD CVE-2021-22785 1576d ago
HIGH
CVE-2020-7534 (CVSS 8.8) — A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could...
NVD CVE-2020-7534 1583d ago
HIGH
CVE-2022-23307 (CVSS 8.8) — CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chain...
NVD CVE-2022-23307CVE-2020-9493 1600d ago
CRITICAL
CVE-2022-23305 (CVSS 9.8) — By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter whe...
NVD CVE-2022-23305 1600d ago
HIGH
CVE-2022-23302 (CVSS 8.8) — JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the att...
NVD CVE-2022-23302CVE-2021-4104 1600d ago
HIGH
CVE-2022-21840 (CVSS 8.8) — Microsoft Office Remote Code Execution Vulnerability
NVD CVE-2022-21840 1607d ago
HIGH
CVE-2021-45450 (CVSS 7.5) — In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow ...
NVD CVE-2021-45450 1629d ago
CRITICAL
CVE-2021-44732 (CVSS 9.8) — Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an m...
NVD CVE-2021-44732 1630d ago
HIGH
CVE-2021-43875 (CVSS 7.8) — Microsoft Office Graphics Remote Code Execution Vulnerability
NVD CVE-2021-43875 1635d ago
HIGH
CVE-2021-43256 (CVSS 7.8) — Microsoft Excel Remote Code Execution Vulnerability
NVD CVE-2021-43256 1635d ago
HIGH
CVE-2021-4104 (CVSS 7.5) — JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has wr...
NVD CVE-2021-4104CVE-2021-44228 1636d ago
HIGH
CVE-2021-44149 (CVSS 7.8) — An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU drive...
NVD CVE-2021-44149 1642d ago
HIGH
CVE-2021-36133 (CVSS 7.1) — The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several mod...
NVD CVE-2021-36133 1642d ago
HIGH
CVE-2021-4019 (CVSS 7.8) — vim is vulnerable to Heap-based Buffer Overflow
NVD CVE-2021-4019 1649d ago
HIGH
CVE-2021-22792 (CVSS 7.5) — A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modico...
NVD CVE-2021-22792 1738d ago
CRITICAL
CVE-2019-25052 (CVSS 9.1) — In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call updat...
NVD CVE-2019-25052 1761d ago
HIGH
CVE-2021-22926 (CVSS 7.5) — libcurl-using applications can ask for a specific client certificate to be used in a transfer. This ...
NVD CVE-2021-22926 1766d ago
CRITICAL
CVE-2021-33485 (CVSS 9.8) — CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
NVD CVE-2021-33485 1768d ago
CRITICAL
CVE-2021-22779 (CVSS 9.1) — Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions p...
NVD CVE-2021-22779 1789d ago
HIGH
CVE-2021-33012 (CVSS 8.6) — Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending...
NVD CVE-2021-33012 1794d ago
CRITICAL
CVE-2021-22768 (CVSS 9.8) — A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and ne...
NVD CVE-2021-22768CVE-2021-22767 1821d ago
CRITICAL
CVE-2021-22767 (CVSS 9.8) — A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and ne...
NVD CVE-2021-22767CVE-2021-2276 1821d ago
HIGH
CVE-2021-22766 (CVSS 7.5) — A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and ne...
NVD CVE-2021-22766 1821d ago
CRITICAL
CVE-2021-22765 (CVSS 9.8) — A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and ne...
NVD CVE-2021-22765 1821d ago
CRITICAL
CVE-2021-22763 (CVSS 9.8) — A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogi...
NVD CVE-2021-22763 1821d ago
HIGH
CVE-2021-32926 (CVSS 7.5) — When an authenticated password change request takes place, this vulnerability could allow the attack...
NVD CVE-2021-32926 1830d ago
CRITICAL
CVE-2020-15782 (CVSS 9.8) — A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMA...
NVD CVE-2020-15782 1835d ago
HIGH
CVE-2021-27386 (CVSS 7.5) — A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPL...
NVD CVE-2021-27386 1852d ago
HIGH
CVE-2021-27385 (CVSS 7.5) — A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPL...
NVD CVE-2021-27385 1852d ago
CRITICAL
CVE-2021-27384 (CVSS 9.8) — A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPL...
NVD CVE-2021-27384 1852d ago
HIGH
CVE-2021-27383 (CVSS 7.5) — A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPL...
NVD CVE-2021-27383 1852d ago
TL;DR
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. Due: 2026-06-05. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2022-0492actively-exploited
Read full story ↗