Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Fedora CRITICAL 9.8
CVE-2022-4170

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to…

Mitigation only
Fix from $2,300 2022-12-09
Flir Ax8 Firmware CRITICAL 9.8
CVE-2022-4364

A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of th…

Fix: 1.46.16+
Fix from $2,300 2022-12-08
Manifoldcf MEDIUM 5.3
CVE-2022-45910

Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory …

Fix: after 2.23
Fix from $1,600 2022-12-07
Linux Kernel MEDIUM 6.5
CVE-2022-3643

Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux bas…

Fix: 4.9.336 / 4.14.302+
Fix from $1,600 2022-12-07
Cacti CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …

Fix: 1.2.23+
Fix from $2,300 2022-12-05
Proxmox Mail Gateway HIGH 7.1
CVE-2022-35507

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote …

Fix: 4.1-3+
Fix from $1,950 2022-12-04
Discourse Bbcode CRITICAL 9.8
CVE-2022-46162

discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with …

Fix: 2022-11-30+
Fix from $2,300 2022-11-30
Xwiki HIGH 8.8
CVE-2022-41934

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly access…

Fix: 13.10.8 / 14.4.3+
Fix from $1,950 2022-11-23
Microweber HIGH 8.8
CVE-2022-33012

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

No fix yet
Fix from $1,950 2022-11-22
Cgi HIGH 8.8
CVE-2021-33621

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that…

Fix: 0.1.0.2 / 0.2.2+
Fix from $1,950 2022-11-18
Parse Server CRITICAL 9.8
CVE-2022-41878

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywor…

Fix: 4.10.19 / 5.3.2+
Fix from $2,300 2022-11-10
Splunk MEDIUM 5.4
CVE-2022-43562

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Email Security Appliance Firmware MEDIUM 5.3
CVE-2022-20772

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to con…

Fix: 14.0.3-015 / 14.2.0-217+
Fix from $1,600 2022-11-04
Keystone CRITICAL 9.8
CVE-2022-39382

Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security…

Patch available
Fix from $2,300 2022-11-03
Spark MEDIUM 5.4
CVE-2022-31777

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScri…

Fix: 3.2.2+
Fix from $1,600 2022-11-01
Hubshare HIGH 8.8
CVE-2022-39016

Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF u…

Fix: 3.3.10.9+
Fix from $1,950 2022-10-31
C200 Firmware CRITICAL 9.8
CVE-2021-38395

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allo…

Mitigation only
Fix from $2,300 2022-10-28
Flume CRITICAL 9.8
CVE-2022-42468

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…

Fix: after 1.10.1
Fix from $2,300 2022-10-26
Octoprint MEDIUM 6.0
CVE-2022-3607

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.

Fix: 1.8.3+
Fix from $1,600 2022-10-19
GitLab CRITICAL 9.9
CVE-2022-2992EPSS 86%

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to ach…

Fix: 15.1.6 / 15.2.4+
Fix from $2,300 2022-10-17
Redirection For Contact Form 7 HIGH 7.5
CVE-2021-36913

Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows att…

Fix: 2.6.0+
Fix from $1,950 2022-10-11
Vince MEDIUM 5.4
CVE-2022-40248

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using …

Fix: 1.50.4+
Fix from $1,600 2022-10-10
Vince MEDIUM 5.4
CVE-2022-40257

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted e…

Fix: 1.50.4+
Fix from $1,600 2022-10-10
Mybb HIGH 7.2
CVE-2022-39265

MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, i…

Fix: 1.8.31+
Fix from $1,950 2022-10-06
Bigbluebutton CRITICAL 9.8
CVE-2020-27602

BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

Fix: 2.2.7+
Fix from $2,300 2022-09-29
Swiftnio HIGH 7.5
CVE-2022-3215

NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server a…

Fix: 2.29.1 / 2.39.1+
Fix from $1,950 2022-09-28
Rt Ax88u Firmware MEDIUM 6.5
CVE-2021-41437

An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an…

Fix: 3.0.0.4.388.20558+
Fix from $1,600 2022-09-26
Glpi CRITICAL 9.8
CVE-2022-35914 KEVEPSS 100%

/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

Fix: after 10.0.2
Fix from $2,300 2022-09-19
Ghas To Csv CRITICAL 9.8
CVE-2022-39217

some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security API and shoves it into a CSV…

Fix: 1+
Fix from $2,300 2022-09-17
Feehi Cms MEDIUM 6.1
CVE-2022-38796

A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing passwor…

No fix yet
Fix from $1,600 2022-09-14