• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-24422
2022-06-07
N/A
9.8 CRITICAL
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.
CVE-2022-24421
Dell, Vostro 3669 Firmware
Xps_7390_firmware, Xps_7390, Emc_integrated_data_protection_appliance_firmware, Emc_idpa_dp4400, Emc_idpa_dp5800, Emc_idpa_dp8300, Emc_idpa_dp8800, Emc_vnx2_firmware, Emc_vnx2, Chengming_3967_firmware
2022-03-18
N/A
7.8 HIGH
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
CVE-2022-24420
Dell, Vostro 3669 Firmware
Xps_7390_firmware, Xps_7390, Emc_integrated_data_protection_appliance_firmware, Emc_idpa_dp4400, Emc_idpa_dp5800, Emc_idpa_dp8300, Emc_idpa_dp8800, Emc_vnx2_firmware, Emc_vnx2, Chengming_3967_firmware
2022-03-18
N/A
7.8 HIGH
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
CVE-2022-2442
2022-09-10
N/A
7.2 HIGH
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
CVE-2022-24419
Dell, Vostro 3669 Firmware
Xps_7390_firmware, Xps_7390, Emc_integrated_data_protection_appliance_firmware, Emc_idpa_dp4400, Emc_idpa_dp5800, Emc_idpa_dp8300, Emc_idpa_dp8800, Emc_vnx2_firmware, Emc_vnx2, Chengming_3967_firmware
2022-03-18
N/A
7.8 HIGH
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
CVE-2022-24418
2022-06-07
N/A
6.7 MEDIUM
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
CVE-2022-24417
2022-06-07
N/A
6.7 MEDIUM
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
CVE-2022-24416
Dell, Vostro 3669 Firmware
Xps_7390_firmware, Xps_7390, Emc_integrated_data_protection_appliance_firmware, Emc_idpa_dp4400, Emc_idpa_dp5800, Emc_idpa_dp8300, Emc_idpa_dp8800, Emc_vnx2_firmware, Emc_vnx2, Chengming_3967_firmware
2022-03-18
N/A
7.8 HIGH
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
CVE-2022-24415
Dell, Vostro 3669 Firmware
Xps_7390_firmware, Xps_7390, Emc_integrated_data_protection_appliance_firmware, Emc_idpa_dp4400, Emc_idpa_dp5800, Emc_idpa_dp8300, Emc_idpa_dp8800, Emc_vnx2_firmware, Emc_vnx2, Chengming_3967_firmware
2022-03-18
N/A
7.8 HIGH
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.
CVE-2022-24414
2022-06-07
N/A
6.5 MEDIUM
Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. Tokens should not be used in request URL to avoid such attacks.
« Previous 1 … 10,504 10,505 10,506 10,507 10,508 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE