CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2022-21999Hoch7.8
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-21971Hoch7.8
Windows Runtime Remote Code Execution Vulnerability
- CVE-2022-24682Mittel6.1
Es wurde ein Problem in der Calendar-Funktion in Zimbra Collaboration Suite 8.8.x vor 8.8.15 Patch 30 (Update 1) entdeckt, das ab Dezember 2021 in freier Wildbahn ausgenutzt wurde. Ein Angreifer konnte HTML mit ausführbarem JavaScript in Elementattributen platzieren. Dieses Markup wird unescaped, wodurch beliebiges Markup in das Dokument injiziert wird.
- CVE-2021-4034Hoch7.8
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
- CVE-2021-40407Hoch7.2
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.
- CVE-2021-22600Mittel6.6
Ein Double-free-Bug in packet_set_ring() in net/packet/af_packet.c kann von einem lokalen Benutzer durch präparierte Syscalls ausgenutzt werden, um Privilegien zu eskalieren oder einen Denial of Service zu verursachen. Wir empfehlen ein Upgrade des Kernels über die betroffenen Versionen hinaus oder einen Rebuild ab ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
- CVE-2021-35587Kritisch9.8
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2022-23227Kritisch9.8
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
- CVE-2022-23134Niedrig3.7
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
- CVE-2022-23131Kritisch9.1
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
- CVE-2022-21919Hoch7.0
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-21882Hoch7.0
Win32k Elevation of Privilege Vulnerability
- CVE-2022-22265Mittel5.0
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
- CVE-2021-35247Mittel4.3
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
- CVE-2021-44168Niedrig3.3
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.
- CVE-2021-44207Hoch8.1
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
- CVE-2021-22054Hoch7.5
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
- CVE-2021-1048Hoch7.8
In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel
- CVE-2021-0920Mittel6.4
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel
- CVE-2021-43891Hoch7.8
Visual Studio Code Remote Code Execution-Schwachstelle
This product uses the NVD API but is not endorsed or certified by the NVD.