Vulnerability index

Browse CVEs

4,971 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 5.4 CVE-2022-34165 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP… Websphere Application Server 22.0.0.9+ Fix from $1,6002022-09-09 HIGH 8.8 CVE-2022-36084 cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prio… Cruddl 2.7.0 / 3.0.2+ Fix from $1,9502022-09-08 HIGH 7.2 CVE-2022-37108 An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permis… Snypr No fix yet Fix from $1,9502022-09-07 CRITICAL 9.8 CVE-2022-37240 MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter. Security Gateway For Email Servers No fix yet Fix from $2,3002022-08-25 CRITICAL 9.8 CVE-2022-37242 MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter. Security Gateway For Email Servers No fix yet Fix from $2,3002022-08-25 CRITICAL 9.8 CVE-2022-34773 Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addresses to the DB. This is an ex… Tabit 3.27.0+ Fix from $2,3002022-08-22 MEDIUM 6.5 CVE-2022-32453 HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via … Office after 10.8.5 Fix from $1,6002022-08-18 HIGH 8.8 CVE-2022-38357 Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection attack, via the url paramete… Eyes Of Network Web No fix yet Fix from $1,9502022-08-15 MEDIUM 5.4 CVE-2022-38191 There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML … Portal For Arcgis after 10.9 Fix from $1,6002022-08-15 MEDIUM 5.0 CVE-2022-35954 The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter… Toolkit 1.9.1+ Fix from $1,6002022-08-15 MEDIUM 5.3 CVE-2022-35948 undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsan… Undici 5.8.2+ Fix from $1,6002022-08-15 CRITICAL 9.1 CVE-2022-36323 Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject… Scalance M 800 Firmware 2.3.1+ Fix from $2,3002022-08-10 HIGH 7.2 CVE-2022-31658 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr… Identity Manager Patch available Fix from $1,9502022-08-05 HIGH 7.2 CVE-2022-31665 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr… Identity Manager Patch available Fix from $1,9502022-08-05 HIGH 7.2 CVE-2022-35735 In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with… Big Ip Access Policy Manager 14.1.5.1 / 15.1.6.1+ Fix from $1,9502022-08-04 CRITICAL 9.8 CVE-2022-31179 Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts… Shescape 1.5.8+ Fix from $2,3002022-08-01 CRITICAL 9.8 CVE-2022-31180 Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolatin… Shescape 1.5.8+ Fix from $2,3002022-08-01 CRITICAL 9.8 CVE-2022-31181EPSS 6% PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerabilit… Prestashop 1.7.8.7+ Fix from $2,3002022-08-01 MEDIUM 5.4 CVE-2022-36302 File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different re… Bf Os after 3.83 Fix from $1,6002022-08-01 HIGH 8.8 CVE-2021-40336 A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP respon… Modular Switchgear Monitoring Firmware after 2.2.0 Fix from $1,9502022-07-25 CRITICAL 9.8 CVE-2016-15004 A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown f… Infinitewp Client No fix yet Fix from $2,3002022-07-23 HIGH 8.8 CVE-2022-22360 IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By … Partner Engagement Manager 6.1.2.5 / 6.2.0.3+ Fix from $1,9502022-07-19 MEDIUM 5.4 CVE-2021-39028 IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper … Engineering Lifecycle Optimization Publishing Patch available Fix from $1,6002022-07-14 HIGH 8.8 CVE-2022-31593 SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker co… Business One Mitigation only Fix from $1,9502022-07-12 HIGH 7.8 CVE-2021-36668 URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App. Insync Client 5.9.3 / 7.0.1+ Fix from $1,9502022-07-12 MEDIUM 6.5 CVE-2022-34466 A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12)… Mendix 9.15.0+ Fix from $1,6002022-07-12 CRITICAL 9.8 CVE-2022-34914 Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {c… Webswing 20.1.16 / 20.2.19+ Fix from $2,3002022-07-08 HIGH 8.8 CVE-2022-33011 Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack. Known after 1.3.1 Fix from $1,9502022-07-08 CRITICAL 9.8 CVE-2022-31126EPSS 50% Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut… Roxy Wi 6.1.1.0+ Fix from $2,3002022-07-06 MEDIUM 6.5 CVE-2022-34903 GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g.… Fedora after 2.3.6 Fix from $1,6002022-07-01