Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Angry Yack Logo
Total 34640 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32582 1 Intel 78 Nuc 11 Performance Kit Nuc11pahi3, Nuc 11 Performance Kit Nuc11pahi30z, Nuc 11 Performance Kit Nuc11pahi30z Firmware and 75 more 2024-11-21 N/A 5.3 MEDIUM
Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access.
CVE-2022-32564 1 Couchbase 1 Couchbase Server 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.
CVE-2022-32561 1 Couchbase 1 Couchbase Server 2024-11-21 3.5 LOW 4.9 MEDIUM
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.
CVE-2022-32558 1 Couchbase 1 Couchbase Server 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.
CVE-2022-32554 1 Purestorage 2 Purity\/\/fa, Purity\/\/fb 2024-11-21 10.0 HIGH 9.8 CRITICAL
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to possibly exposed credentials for accessing the product’s management interface. The password may be known outside Pure Storage and could be used on an affected system, if reachable, to execute arbitrary ...

Show More

CVE-2022-32553 1 Purestorage 2 Purity\/\/fa, Purity\/\/fb 2024-11-21 9.0 HIGH 8.8 HIGH
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to a privilege escalation via the manipulation of environment variables which can be exploited by a logged-in user to escape a restricted shell to an unrestricted shell with root privileges. No other Pure ...

Show More

CVE-2022-32552 1 Purestorage 2 Purity\/\/fa, Purity\/\/fb 2024-11-21 9.0 HIGH 8.8 HIGH
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to a privilege escalation via the manipulation of Python environment variables which can be exploited by a logged-in user to escape a restricted shell to an unrestricted shell with root privileges. No oth ...

Show More

CVE-2022-32550 1 1password 6 1password, 1password In The Browser, Command-line and 3 more 2024-11-21 5.8 MEDIUM 4.8 MEDIUM
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.
CVE-2022-32533 1 Apache 1 Jetspeed 2024-11-21 7.5 HIGH 9.8 CRITICAL
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue
CVE-2022-32511 2 Fedoraproject, Jmespath Project 2 Fedora, Jmespath 2024-11-21 7.5 HIGH 9.8 CRITICAL
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.
CVE-2022-32481 1 Dell 1 Powerprotect Cyber Recovery 2024-11-21 7.2 HIGH 7.8 HIGH
Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.
CVE-2022-32420 1 College Management System Project 1 College Management System 2024-11-21 6.8 MEDIUM 8.8 HIGH
College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerability is exploited via a crafted PHP file.
CVE-2022-32412 1 Hongcms Project 1 Hongcms 2024-11-21 6.5 MEDIUM 7.2 HIGH
An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.
CVE-2022-32411 1 Hongcms Project 1 Hongcms 2024-11-21 6.5 MEDIUM 7.2 HIGH
An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.
CVE-2022-32295 1 Amperecomputing 4 Ampere Altra, Ampere Altra Firmware, Ampere Altra Max and 1 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.
CVE-2022-32291 1 Realnetworks 1 Realplayer 2024-11-21 6.8 MEDIUM 8.8 HIGH
In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.
CVE-2022-32283 1 Cybozu 1 Office 2024-11-21 N/A 4.3 MEDIUM
Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Cabinet via unspecified vectors.
CVE-2022-32278 2 Debian, Xfce 2 Debian Linux, Exo 2024-11-21 6.8 MEDIUM 8.8 HIGH
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
CVE-2022-32268 1 Starwindsoftware 1 Starwind San \& Nas 2024-11-21 9.0 HIGH 8.8 HIGH
StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a new hostname parameter. It goes directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges.
CVE-2022-32265 1 Qdecoder Project 1 Qdecoder 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
CVE-2022-32263 1 Pexip 1 Pexip Infinity 2024-11-21 N/A 7.5 HIGH
Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.
CVE-2022-32244 1 Sap 1 Businessobjects Business Intelligence 2024-11-21 N/A 5.2 MEDIUM
Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs the attacker to have high privilege access to the same physical/logical network to access information which would otherwise be restricted, leading to low impact on confidentiality and high impact on integrity of the application.
CVE-2022-32189 1 Golang 1 Go 2024-11-21 N/A 7.5 HIGH
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
CVE-2022-32158 1 Splunk 1 Splunk 2024-11-21 7.5 HIGH 9.0 CRITICAL
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.
CVE-2022-32148 1 Golang 1 Go 2024-11-21 N/A 6.5 MEDIUM
Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.
CVE-2022-32089 2 Fedoraproject, Mariadb 2 Fedora, Mariadb 2024-11-21 5.0 MEDIUM 7.5 HIGH
MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
CVE-2022-32088 2 Debian, Mariadb 2 Debian Linux, Mariadb 2024-11-21 5.0 MEDIUM 7.5 HIGH
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.
CVE-2022-32087 2 Debian, Mariadb 2 Debian Linux, Mariadb 2024-11-21 5.0 MEDIUM 7.5 HIGH
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.
CVE-2022-32086 1 Mariadb 1 Mariadb 2024-11-21 5.0 MEDIUM 7.5 HIGH
MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.
CVE-2022-32085 2 Debian, Mariadb 2 Debian Linux, Mariadb 2024-11-21 5.0 MEDIUM 7.5 HIGH
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.
CVE-2022-32084 3 Debian, Fedoraproject, Mariadb 3 Debian Linux, Fedora, Mariadb 2024-11-21 5.0 MEDIUM 7.5 HIGH
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
CVE-2022-32083 2 Debian, Mariadb 2 Debian Linux, Mariadb 2024-11-21 5.0 MEDIUM 7.5 HIGH
MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.
CVE-2022-32020 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via ip/car-rental-management-system/admin/ajax.php?action=save_settings.
CVE-2022-31973 1 Online Fire Reporting System Project 1 Online Fire Reporting System 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
Online Fire Reporting System v1.0 is vulnerable to Delete any file via /ofrs/classes/Master.php?f=delete_img.
CVE-2022-31966 1 Chatbot App With Suggestion Project 1 Chatbot App With Suggestion 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
ChatBot App with Suggestion v1.0 is vulnerable to Delete any file via /simple_chat_bot/classes/Master.php?f=delete_img.
CVE-2022-31945 1 Rescue Dispatch Management System Project 1 Rescue Dispatch Management System 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
Rescue Dispatch Management System v1.0 is vulnerable to Delete any file via /rdms/classes/Master.php?f=delete_img.
CVE-2022-31849 1 Mercurycom 2 Mipc451-4, Mipc451-4 Firmware 2024-11-21 6.5 MEDIUM 8.8 HIGH
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
CVE-2022-31791 1 Watchguard 1 Fireware 2024-11-21 N/A 7.8 HIGH
WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access) to elevate their privileges and execute code with root permissions. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
CVE-2022-31790 1 Watchguard 1 Fireware 2024-11-21 N/A 7.5 HIGH
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
CVE-2022-31770 1 Ibm 1 App Connect Enterprise Certified Container 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial of service by creating a specially crafted request. IBM X-Force ID: 228221.