Vulnerabilidades CVE
Base de dados CVE enriquecida com CISA KEV e NVD
| CVE ID | CVSS | Severidade | KEV | Avistamentos |
|---|---|---|---|---|
| CVE-2021-36958 <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could r... | 7.8 | HIGH | — | 0 |
| CVE-2021-0584 In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This could lead to local information disclosure with no additional execution privileges... | 5.5 | MEDIUM | — | 0 |
| CVE-2021-0641 In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclos... | 5.5 | MEDIUM | — | 0 |
| CVE-2021-0642 In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information di... | 5.5 | MEDIUM | — | 0 |
| CVE-2013-6404 Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via th... | N/A | NONE | — | 0 |
| CVE-2022-1223 Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | 6.5 | MEDIUM | — | 0 |
| CVE-2021-38162 SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes allow an unauthenticat... | 8.9 | HIGH | — | 0 |
| CVE-2021-31843 Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have acce... | 7.3 | HIGH | — | 0 |
| CVE-2021-38180 SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-24932 An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-41372 A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files ... | 7.6 | HIGH | — | 0 |
| CVE-2022-0178 Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8. | 6.3 | MEDIUM | — | 0 |
| CVE-2021-42306 An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application ... | 8.1 | HIGH | — | 0 |
| CVE-2021-43113 iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-24750 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which cou... | 8.8 | HIGH | — | 0 |
| CVE-2022-0121 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1. | 8.0 | HIGH | — | 0 |
| CVE-2021-40006 Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality. | 4.6 | MEDIUM | — | 0 |
| CVE-2025-8587 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows SQL Injection.This issue affect... | 8.6 | HIGH | — | 0 |
| CVE-2021-40014 The bone voice ID trusted application (TA) has a heap overflow vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | 7.5 | HIGH | — | 0 |
| CVE-2021-40027 The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability may affect data confidentiality. | 7.5 | HIGH | — | 0 |
| CVE-2021-40032 The bone voice ID TA has a vulnerability in information management,Successful exploitation of this vulnerability may affect data confidentiality. | 7.5 | HIGH | — | 0 |
| CVE-2022-22988 File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through t... | 7.7 | HIGH | — | 0 |
| CVE-2022-22989 My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by ... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-22529 SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD a... | 6.1 | MEDIUM | — | 0 |
| CVE-2022-22530 The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to ... | 8.1 | HIGH | — | 0 |
| CVE-2022-22531 The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to ... | 8.1 | HIGH | — | 0 |
| CVE-2021-41807 Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forci... | 7.5 | HIGH | — | 0 |
| CVE-2021-41808 In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled b... | 2.0 | LOW | — | 0 |
| CVE-2025-12357 By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers tha... | 6.3 | MEDIUM | — | 0 |
| CVE-2021-41809 SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities. | 3.5 | LOW | — | 0 |
| CVE-2021-31854 A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed in... | 7.7 | HIGH | — | 0 |
| CVE-2022-0282 Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11. | 4.3 | MEDIUM | — | 0 |
| CVE-2021-36342 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM... | 7.5 | HIGH | — | 0 |
| CVE-2021-36343 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM... | 7.5 | HIGH | — | 0 |
| CVE-2022-0338 Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3. | 4.3 | MEDIUM | — | 0 |
| CVE-2022-0355 Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1. | 8.8 | HIGH | — | 0 |
| CVE-2022-0536 Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8. | 2.6 | LOW | — | 0 |
| CVE-2022-23631 superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson inp... | 9.0 | CRITICAL | — | 0 |
| CVE-2022-22528 SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to ... | 7.8 | HIGH | — | 0 |
| CVE-2022-0565 Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1. | 7.6 | HIGH | — | 0 |
| CVE-2022-0569 Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9. | 5.3 | MEDIUM | — | 0 |
| CVE-2022-0579 Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9. | 6.5 | MEDIUM | — | 0 |
| CVE-2022-0580 Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0. | 7.1 | HIGH | — | 0 |
| CVE-2022-0588 Missing Authorization in Packagist librenms/librenms prior to 22.2.0. | 7.1 | HIGH | — | 0 |
| CVE-2022-0611 Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11. | 6.3 | MEDIUM | — | 0 |
| CVE-2021-39298 A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used b... | 8.8 | HIGH | — | 0 |
| CVE-2022-0762 Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3. | 5.5 | MEDIUM | — | 0 |
| CVE-2021-25042 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or... | 5.4 | MEDIUM | — | 0 |
| CVE-2022-0528 Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1. | 6.5 | MEDIUM | — | 0 |
| CVE-2022-1252 Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms lead... | 8.2 | HIGH | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.