Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-42886
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without author…
Ex1200t Firmware
No fix yet
CRITICAL 9.8
CVE-2022-26869
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploi…
Powerstoreos
2.1.1.0+
HIGH 7.5
CVE-2022-27775
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool …
Curl
after 7.82.0
MEDIUM 5.3
CVE-2022-29235
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able t…
Bigbluebutton
2.3.18+
MEDIUM 6.5
CVE-2022-29232
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circum…
Bigbluebutton
2.3.9+
MEDIUM 6.5
CVE-2022-24414
Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies …
Cloudlink
after 7.1.3
MEDIUM 6.5
CVE-2022-20821 KEVEPSS 12%
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is…
Ios Xr
Mitigation only
HIGH 8.1
CVE-2022-29248
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that …
Drupal
6.5.6 / 7.4.3+
HIGH 7.5
CVE-2022-1815EPSS 6%
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
Drawio
18.1.2+
HIGH 7.5
CVE-2022-29567
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through…
Vaadin
after 23.0.8
CRITICAL 10.0
CVE-2022-29165
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with versi…
Argo Cd
2.1.15 / 2.2.9+
MEDIUM 6.1
CVE-2022-1774
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
Drawio
18.0.7+
HIGH 7.5
CVE-2022-30990
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before bui…
Cyber Protect
15+
HIGH 8.8
CVE-2022-23067
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite li…
Tooljet
after 1.2.2
MEDIUM 5.3
CVE-2020-4957
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks again…
Security Identity Governance And Intelligence
Patch available
MEDIUM 5.3
CVE-2022-30334
Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers. NOTE: although this was fixe…
Brave
1.34+
MEDIUM 5.5
CVE-2022-27875
On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow…
Access For Android
3.0.8+
MEDIUM 5.3
CVE-2022-25990
On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have re…
F5os A
No fix yet
MEDIUM 5.3
CVE-2021-39020
IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unaut…
Guardium Data Encryption
after 4.0.0.7
MEDIUM 6.7
CVE-2022-25787
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack conne…
Gatemanager 4250 Firmware
9.7.622134021+
MEDIUM 5.5
CVE-2022-0882
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It …
Fuchsia
4.1.1+
CRITICAL 9.8
CVE-2021-43938
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or auth…
Scada Server
Mitigation only
HIGH 7.1
CVE-2022-1353
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain…
Linux Kernel
5.17+
HIGH 8.8
CVE-2021-43937
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intenti…
Scada Server
No fix yet
MEDIUM 5.3
CVE-2022-22276
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
Tz300p Firmware
7.0.1 / 7.0.1.0+
MEDIUM 5.3
CVE-2022-22277
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
Tz300p Firmware
6.5.4.10 / 7.0.1.0+
HIGH 7.5
CVE-2021-34589
In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authenticatio…
Cc612 Firmware
5.11.2 / 5.12.5+
MEDIUM 5.3
CVE-2022-23711
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring …
Kibana
7.17.3 / 8.1.3+
HIGH 7.5
CVE-2022-24867
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you …
Glpi
10.0.0+
MEDIUM 6.5
CVE-2022-24865
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrie…
Humhub
1.9.4 / 1.10.4+