Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Btcpay Server HIGH 8.8
CVE-2023-0493EPSS 8%

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.

Fix: 1.7.5+
Fix from $1,950 2023-01-26
Tenable.sc MEDIUM 6.5
CVE-2023-0476

A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated …

Fix: after 5.23.1
Fix from $1,600 2023-01-26
Ac1200 R6220 Firmware MEDIUM 6.1
CVE-2022-47052

The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflec…

No fix yet
Fix from $1,600 2023-01-26
Common Desktop Environment HIGH 7.1
CVE-2023-24040

dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of availabl…

No fix yet
Fix from $1,950 2023-01-21
Swift Foundation HIGH 8.8
CVE-2022-3918

A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URLRequest headers. In this vuln…

Fix: 5.7.3+
Fix from $1,950 2023-01-20
Reprise License Manager MEDIUM 6.5
CVE-2021-37499

CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that all…

Fix: 17.0+
Fix from $1,600 2023-01-20
Asyncos MEDIUM 5.3
CVE-2023-20057

A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, rem…

Mitigation only
Fix from $1,600 2023-01-20
Webmentions CRITICAL 9.8
CVE-2017-20174

A vulnerability was found in bastianallgeier Kirby Webmentions Plugin and classified as problematic. Affected by this issue is some unknown functiona…

Fix: 2017-02-01+
Fix from $2,300 2023-01-19
Async Http Client HIGH 7.5
CVE-2023-0040

Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was…

Fix: 1.4.1 / 1.9.1+
Fix from $1,950 2023-01-18
Ldap Integration With Active Directory And Openldap HIGH 7.5
CVE-2023-23749

The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly san…

Mitigation only
Fix from $1,950 2023-01-17
Galaxy CRITICAL 9.8
CVE-2015-10062

A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component …

Fix: 14.10.1+
Fix from $2,300 2023-01-17
Superset MEDIUM 5.4
CVE-2022-43720

An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the t…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Radare2 HIGH 7.8
CVE-2023-0302

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.

Fix: 5.8.2+
Fix from $1,950 2023-01-15
Gitlearn MEDIUM 6.5
CVE-2015-10040

A vulnerability was found in gitlearn. It has been declared as problematic. This vulnerability affects the function getGrade/getOutOf of the file scr…

Fix: 2015-06-09+
Fix from $1,600 2023-01-13
Nvidia Isaac Sim HIGH 7.8
CVE-2022-42268

Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications all…

Fix: 2022.2 / 2022.2.0+
Fix from $1,950 2023-01-13
Ttrrs Auth Ldap CRITICAL 9.8
CVE-2015-10027

A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality…

Patch available
Fix from $2,300 2023-01-07
Superdome Flex 280 Firmware HIGH 7.8
CVE-2022-37933

A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to …

Fix: 1.40.60 / 3.60.50+
Fix from $1,950 2023-01-05
Mermaid MEDIUM 5.4
CVE-2022-46180

Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid synta…

Fix: 1.1.0+
Fix from $1,600 2023-01-04
Fortiweb MEDIUM 5.4
CVE-2022-42471

An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.…

Fix: after 6.3.21
Fix from $1,600 2023-01-03
Centralized Salesforce Development Framework CRITICAL 9.8
CVE-2016-15007

A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this vulnerability is the functio…

Fix: 2016-06-20+
Fix from $2,300 2023-01-02
Macgeiger HIGH 7.8
CVE-2017-20161

A vulnerability classified as problematic has been found in rofl0r MacGeiger. Affected is the function dump_wlan_at of the file macgeiger.c of the co…

Fix: 2017-12-02+
Fix from $1,950 2023-01-02
Froxlor MEDIUM 5.4
CVE-2022-4864

Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

Fix: after 0.10.38.3
Fix from $1,600 2022-12-30
Merou CRITICAL 9.8
CVE-2022-4768

A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_ke…

Fix: 2022-03-28+
Fix from $2,300 2022-12-27
Firefox HIGH 8.8
CVE-2022-46873

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise prote…

Fix: 108.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-40958

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite c…

Fix: 102.3 / 105.0+
Fix from $1,600 2022-12-22
Karaf CRITICAL 9.8
CVE-2022-40145

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function …

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-12-21
Node Whois CRITICAL 9.8
CVE-2020-36618

A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulatio…

Patch available
Fix from $2,300 2022-12-19
Android HIGH 7.8
CVE-2022-42544

In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. T…

Patch available
Fix from $1,950 2022-12-16
Rfc6902 CRITICAL 9.8
CVE-2021-4245

A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation le…

Fix: 5.0.0+
Fix from $2,300 2022-12-15
Polarion Alm MEDIUM 5.4
CVE-2022-46265

A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host header injection vulnerability…

Fix: 2304.0+
Fix from $1,600 2022-12-13