Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-34844
In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elas…
Big Ip Access Policy Manager
15.1.6.1 / 16.1.3.1+
MEDIUM 6.5
CVE-2022-34851
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BI…
Big Ip Access Policy Manager
14.1.5.1 / 15.1.6.1+
MEDIUM 6.5
CVE-2022-30535
In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to …
Nginx Ingress Controller
2.3.0+
CRITICAL 9.1
CVE-2022-35924
NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in…
Next Auth
3.29.10 / 4.10.3+
HIGH 7.4
CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peer…
Fedora
3.2.5+
CRITICAL 9.1
CVE-2022-31321
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or caus…
Bolt
after 5.7
MEDIUM 5.5
CVE-2022-34164
IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X-Force ID: 229338.
Cics Tx
Patch available
CRITICAL 9.8
CVE-2022-27255EPSS 37%
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker…
Ecos Rsdk Firmware
Mitigation only
HIGH 8.6
CVE-2020-6998
The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficient…
Armor Compact Guardlogix 5370 Firmware
after 33
MEDIUM 6.5
CVE-2022-1500
Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a c…
Chrome
101.0.4951.41+
CRITICAL 9.8
CVE-2022-35649EPSS 8%
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results i…
Moodle
3.9.15 / 3.11.8+
HIGH 7.5
CVE-2022-35650EPSS 49%
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in…
Moodle
3.9.15 / 3.11.8+
CRITICAL 9.8
CVE-2022-36450EPSS 20%
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the UR…
Obsidian
0.15.5+
HIGH 7.5
CVE-2022-31170
OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of r…
Contracts
4.7.1+
HIGH 7.5
CVE-2022-31172
OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `Sig…
Contracts
4.7.1+
MEDIUM 6.7
CVE-2022-20908
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…
Nexus Dashboard
2.2+
MEDIUM 6.7
CVE-2022-20909
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…
Nexus Dashboard
2.2+
MEDIUM 6.5
CVE-2022-20913
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerabi…
Nexus Dashboard
2.2+
MEDIUM 6.5
CVE-2022-22214
An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent…
Junos
12.3 / 20.4+
HIGH 7.8
CVE-2022-34866
Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interp…
Passage Drive
after 1.5.1.0
HIGH 8.2
CVE-2022-35404
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…
Manageengine Opmanager
12.5+
HIGH 7.5
CVE-2022-26655
Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a software abort via a gateway call …
Pexip Infinity
27.3+
MEDIUM 5.3
CVE-2022-32248
Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or…
S\/4hana
Mitigation only
MEDIUM 5.5
CVE-2022-35171
When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application cr…
3d Visual Enterprise Viewer
Mitigation only
HIGH 8.8
CVE-2022-2385
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privile…
Aws Iam Authenticator
0.5.9+
HIGH 7.8
CVE-2022-33703
Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
Android
Mitigation only
HIGH 7.8
CVE-2022-33704
Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.
Android
Mitigation only
HIGH 7.8
CVE-2022-33708
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities…
Galaxy Store
4.5.41.8+
HIGH 7.8
CVE-2022-33709
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities…
Galaxy Store
4.5.41.8+
HIGH 7.8
CVE-2022-33710
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activit…
Galaxy Store
4.5.41.8+