Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 9.8 CVE-2022-4170 The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to… Fedora Mitigation only Fix from $2,3002022-12-09 CRITICAL 9.8 CVE-2022-4364 A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of th… Flir Ax8 Firmware 1.46.16+ Fix from $2,3002022-12-08 MEDIUM 5.3 CVE-2022-45910 Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory … Manifoldcf after 2.23 Fix from $1,6002022-12-07 MEDIUM 6.5 CVE-2022-3643 Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux bas… Linux Kernel 4.9.336 / 4.14.302+ Fix from $1,6002022-12-07 CRITICAL 9.8 CVE-2022-46169 KEVEPSS 100% Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected … Cacti 1.2.23+ Fix from $2,3002022-12-05 HIGH 7.1 CVE-2022-35507 A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote … Proxmox Mail Gateway 4.1-3+ Fix from $1,9502022-12-04 CRITICAL 9.8 CVE-2022-46162 discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with … Discourse Bbcode 2022-11-30+ Fix from $2,3002022-11-30 HIGH 8.8 CVE-2022-41934 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly access… Xwiki 13.10.8 / 14.4.3+ Fix from $1,9502022-11-23 HIGH 8.8 CVE-2022-33012 Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack. Microweber No fix yet Fix from $1,9502022-11-22 HIGH 8.8 CVE-2021-33621 The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that… Cgi 0.1.0.2 / 0.2.2+ Fix from $1,9502022-11-18 CRITICAL 9.8 CVE-2022-41878 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywor… Parse Server 4.10.19 / 5.3.2+ Fix from $2,3002022-11-10 MEDIUM 5.4 CVE-2022-43562 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could le… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 MEDIUM 5.3 CVE-2022-20772 A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to con… Email Security Appliance Firmware 14.0.3-015 / 14.2.0-217+ Fix from $1,6002022-11-04 CRITICAL 9.8 CVE-2022-39382 Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security… Keystone Patch available Fix from $2,3002022-11-03 MEDIUM 5.4 CVE-2022-31777 A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScri… Spark 3.2.2+ Fix from $1,6002022-11-01 HIGH 8.8 CVE-2022-39016 Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF u… Hubshare 3.3.10.9+ Fix from $1,9502022-10-31 CRITICAL 9.8 CVE-2021-38395 Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allo… C200 Firmware Mitigation only Fix from $2,3002022-10-28 CRITICAL 9.8 CVE-2022-42468 Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa… Flume after 1.10.1 Fix from $2,3002022-10-26 MEDIUM 6.0 CVE-2022-3607 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3. Octoprint 1.8.3+ Fix from $1,6002022-10-19 CRITICAL 9.9 CVE-2022-2992EPSS 86% A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to ach… GitLab 15.1.6 / 15.2.4+ Fix from $2,3002022-10-17 HIGH 7.5 CVE-2021-36913 Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows att… Redirection For Contact Form 7 2.6.0+ Fix from $1,9502022-10-11 MEDIUM 5.4 CVE-2022-40248 An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using … Vince 1.50.4+ Fix from $1,6002022-10-10 MEDIUM 5.4 CVE-2022-40257 An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted e… Vince 1.50.4+ Fix from $1,6002022-10-10 HIGH 7.2 CVE-2022-39265 MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, i… Mybb 1.8.31+ Fix from $1,9502022-10-06 CRITICAL 9.8 CVE-2020-27602 BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken. Bigbluebutton 2.2.7+ Fix from $2,3002022-09-29 HIGH 7.5 CVE-2022-3215 NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server a… Swiftnio 2.29.1 / 2.39.1+ Fix from $1,9502022-09-28 MEDIUM 6.5 CVE-2021-41437 An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an… Rt Ax88u Firmware 3.0.0.4.388.20558+ Fix from $1,6002022-09-26 CRITICAL 9.8 CVE-2022-35914 KEVEPSS 100% /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. Glpi after 10.0.2 Fix from $2,3002022-09-19 CRITICAL 9.8 CVE-2022-39217 some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security API and shoves it into a CSV… Ghas To Csv 1+ Fix from $2,3002022-09-17 MEDIUM 6.1 CVE-2022-38796 A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing passwor… Feehi Cms No fix yet Fix from $1,6002022-09-14