Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-4170
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to…
Fedora
Mitigation only
CRITICAL 9.8
CVE-2022-4364
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of th…
Flir Ax8 Firmware
1.46.16+
MEDIUM 5.3
CVE-2022-45910
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory …
Manifoldcf
after 2.23
MEDIUM 6.5
CVE-2022-3643
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux bas…
Linux Kernel
4.9.336 / 4.14.302+
CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …
Cacti
1.2.23+
HIGH 7.1
CVE-2022-35507
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote …
Proxmox Mail Gateway
4.1-3+
CRITICAL 9.8
CVE-2022-46162
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with …
Discourse Bbcode
2022-11-30+
HIGH 8.8
CVE-2022-41934
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly access…
Xwiki
13.10.8 / 14.4.3+
HIGH 8.8
CVE-2022-33012
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
Microweber
No fix yet
HIGH 8.8
CVE-2021-33621
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that…
Cgi
0.1.0.2 / 0.2.2+
CRITICAL 9.8
CVE-2022-41878
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywor…
Parse Server
4.10.19 / 5.3.2+
MEDIUM 5.4
CVE-2022-43562
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le…
Splunk
8.1.12 / 8.2.9+
MEDIUM 5.3
CVE-2022-20772
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to con…
Email Security Appliance Firmware
14.0.3-015 / 14.2.0-217+
CRITICAL 9.8
CVE-2022-39382
Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security…
Keystone
Patch available
MEDIUM 5.4
CVE-2022-31777
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScri…
Spark
3.2.2+
HIGH 8.8
CVE-2022-39016
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF u…
Hubshare
3.3.10.9+
CRITICAL 9.8
CVE-2021-38395
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allo…
C200 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-42468
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…
Flume
after 1.10.1
MEDIUM 6.0
CVE-2022-3607
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.
Octoprint
1.8.3+
CRITICAL 9.9
CVE-2022-2992EPSS 86%
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to ach…
GitLab
15.1.6 / 15.2.4+
HIGH 7.5
CVE-2021-36913
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows att…
Redirection For Contact Form 7
2.6.0+
MEDIUM 5.4
CVE-2022-40248
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using …
Vince
1.50.4+
MEDIUM 5.4
CVE-2022-40257
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted e…
Vince
1.50.4+
HIGH 7.2
CVE-2022-39265
MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, i…
Mybb
1.8.31+
CRITICAL 9.8
CVE-2020-27602
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
Bigbluebutton
2.2.7+
HIGH 7.5
CVE-2022-3215
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server a…
Swiftnio
2.29.1 / 2.39.1+
MEDIUM 6.5
CVE-2021-41437
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an…
Rt Ax88u Firmware
3.0.0.4.388.20558+
CRITICAL 9.8
CVE-2022-35914 KEVEPSS 100%
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
Glpi
after 10.0.2
CRITICAL 9.8
CVE-2022-39217
some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security API and shoves it into a CSV…
Ghas To Csv
1+
MEDIUM 6.1
CVE-2022-38796
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing passwor…
Feehi Cms
No fix yet