Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Websphere Application Server MEDIUM 5.4
CVE-2022-34165

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP…

Fix: 22.0.0.9+
Fix from $1,600 2022-09-09
Cruddl HIGH 8.8
CVE-2022-36084

cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prio…

Fix: 2.7.0 / 3.0.2+
Fix from $1,950 2022-09-08
Snypr HIGH 7.2
CVE-2022-37108

An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permis…

No fix yet
Fix from $1,950 2022-09-07
Security Gateway For Email Servers CRITICAL 9.8
CVE-2022-37240

MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.

No fix yet
Fix from $2,300 2022-08-25
Security Gateway For Email Servers CRITICAL 9.8
CVE-2022-37242

MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.

No fix yet
Fix from $2,300 2022-08-25
Tabit CRITICAL 9.8
CVE-2022-34773

Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addresses to the DB. This is an ex…

Fix: 3.27.0+
Fix from $2,300 2022-08-22
Office MEDIUM 6.5
CVE-2022-32453

HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via …

Fix: after 10.8.5
Fix from $1,600 2022-08-18
Eyes Of Network Web HIGH 8.8
CVE-2022-38357

Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection attack, via the url paramete…

No fix yet
Fix from $1,950 2022-08-15
Portal For Arcgis MEDIUM 5.4
CVE-2022-38191

There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML …

Fix: after 10.9
Fix from $1,600 2022-08-15
Toolkit MEDIUM 5.0
CVE-2022-35954

The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter…

Fix: 1.9.1+
Fix from $1,600 2022-08-15
Undici MEDIUM 5.3
CVE-2022-35948

undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsan…

Fix: 5.8.2+
Fix from $1,600 2022-08-15
Scalance M 800 Firmware CRITICAL 9.1
CVE-2022-36323

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject…

Fix: 2.3.1+
Fix from $2,300 2022-08-10
Identity Manager HIGH 7.2
CVE-2022-31658

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr…

Patch available
Fix from $1,950 2022-08-05
Identity Manager HIGH 7.2
CVE-2022-31665

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr…

Patch available
Fix from $1,950 2022-08-05
Big Ip Access Policy Manager HIGH 7.2
CVE-2022-35735

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with…

Fix: 14.1.5.1 / 15.1.6.1+
Fix from $1,950 2022-08-04
Shescape CRITICAL 9.8
CVE-2022-31179

Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts…

Fix: 1.5.8+
Fix from $2,300 2022-08-01
Shescape CRITICAL 9.8
CVE-2022-31180

Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolatin…

Fix: 1.5.8+
Fix from $2,300 2022-08-01
Prestashop CRITICAL 9.8
CVE-2022-31181EPSS 6%

PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerabilit…

Fix: 1.7.8.7+
Fix from $2,300 2022-08-01
Bf Os MEDIUM 5.4
CVE-2022-36302

File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different re…

Fix: after 3.83
Fix from $1,600 2022-08-01
Modular Switchgear Monitoring Firmware HIGH 8.8
CVE-2021-40336

A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP respon…

Fix: after 2.2.0
Fix from $1,950 2022-07-25
Infinitewp Client CRITICAL 9.8
CVE-2016-15004

A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown f…

No fix yet
Fix from $2,300 2022-07-23
Partner Engagement Manager HIGH 8.8
CVE-2022-22360

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By …

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,950 2022-07-19
Engineering Lifecycle Optimization Publishing MEDIUM 5.4
CVE-2021-39028

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper …

Patch available
Fix from $1,600 2022-07-14
Business One HIGH 8.8
CVE-2022-31593

SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker co…

Mitigation only
Fix from $1,950 2022-07-12
Insync Client HIGH 7.8
CVE-2021-36668

URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

Fix: 5.9.3 / 7.0.1+
Fix from $1,950 2022-07-12
Mendix MEDIUM 6.5
CVE-2022-34466

A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12)…

Fix: 9.15.0+
Fix from $1,600 2022-07-12
Webswing CRITICAL 9.8
CVE-2022-34914

Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {c…

Fix: 20.1.16 / 20.2.19+
Fix from $2,300 2022-07-08
Known HIGH 8.8
CVE-2022-33011

Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack.

Fix: after 1.3.1
Fix from $1,950 2022-07-08
Roxy Wi CRITICAL 9.8
CVE-2022-31126EPSS 50%

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-06
Fedora MEDIUM 6.5
CVE-2022-34903

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g.…

Fix: after 2.3.6
Fix from $1,600 2022-07-01