Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2022-34165
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP…
Websphere Application Server
22.0.0.9+
HIGH 8.8
CVE-2022-36084
cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prio…
Cruddl
2.7.0 / 3.0.2+
HIGH 7.2
CVE-2022-37108
An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permis…
Snypr
No fix yet
CRITICAL 9.8
CVE-2022-37240
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
Security Gateway For Email Servers
No fix yet
CRITICAL 9.8
CVE-2022-37242
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
Security Gateway For Email Servers
No fix yet
CRITICAL 9.8
CVE-2022-34773
Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addresses to the DB. This is an ex…
Tabit
3.27.0+
MEDIUM 6.5
CVE-2022-32453
HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via …
Office
after 10.8.5
HIGH 8.8
CVE-2022-38357
Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection attack, via the url paramete…
Eyes Of Network Web
No fix yet
MEDIUM 5.4
CVE-2022-38191
There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML …
Portal For Arcgis
after 10.9
MEDIUM 5.0
CVE-2022-35954
The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter…
Toolkit
1.9.1+
MEDIUM 5.3
CVE-2022-35948
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsan…
Undici
5.8.2+
CRITICAL 9.1
CVE-2022-36323
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject…
Scalance M 800 Firmware
2.3.1+
HIGH 7.2
CVE-2022-31658
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr…
Identity Manager
Patch available
HIGH 7.2
CVE-2022-31665
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administr…
Identity Manager
Patch available
HIGH 7.2
CVE-2022-35735
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with…
Big Ip Access Policy Manager
14.1.5.1 / 15.1.6.1+
CRITICAL 9.8
CVE-2022-31179
Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts…
Shescape
1.5.8+
CRITICAL 9.8
CVE-2022-31180
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolatin…
Shescape
1.5.8+
CRITICAL 9.8
CVE-2022-31181EPSS 6%
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerabilit…
Prestashop
1.7.8.7+
MEDIUM 5.4
CVE-2022-36302
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different re…
Bf Os
after 3.83
HIGH 8.8
CVE-2021-40336
A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP respon…
Modular Switchgear Monitoring Firmware
after 2.2.0
CRITICAL 9.8
CVE-2016-15004
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown f…
Infinitewp Client
No fix yet
HIGH 8.8
CVE-2022-22360
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By …
Partner Engagement Manager
6.1.2.5 / 6.2.0.3+
MEDIUM 5.4
CVE-2021-39028
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper …
Engineering Lifecycle Optimization Publishing
Patch available
HIGH 8.8
CVE-2022-31593
SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker co…
Business One
Mitigation only
HIGH 7.8
CVE-2021-36668
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
Insync Client
5.9.3 / 7.0.1+
MEDIUM 6.5
CVE-2022-34466
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12)…
Mendix
9.15.0+
CRITICAL 9.8
CVE-2022-34914
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {c…
Webswing
20.1.16 / 20.2.19+
HIGH 8.8
CVE-2022-33011
Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack.
Known
after 1.3.1
CRITICAL 9.8
CVE-2022-31126EPSS 50%
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut…
Roxy Wi
6.1.1.0+
MEDIUM 6.5
CVE-2022-34903
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g.…
Fedora
after 2.3.6