Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2013-4144
There is an object injection vulnerability in swfupload plugin for wordpress.
Swfupload
No fix yet
MEDIUM 6.1
CVE-2022-31108
Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex …
Mermaid
9.1.3+
HIGH 8.8
CVE-2022-31086
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…
Debian Linux
8.0+
HIGH 7.8
CVE-2022-31087
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…
Debian Linux
8.0+
MEDIUM 5.3
CVE-2022-31088
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…
Debian Linux
8.0+
CRITICAL 9.8
CVE-2022-25167
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI L…
Flume
1.10.0+
HIGH 8.8
CVE-2020-36531
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device M…
Sevone Network Performance Management
after 5.7.2.22
HIGH 7.5
CVE-2022-29631
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRe…
Jodd Http
6.2.1+
CRITICAL 9.8
CVE-2020-28246
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email tem…
Form.io
Mitigation only
MEDIUM 6.1
CVE-2022-30991
HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
Cyber Protect
15+
MEDIUM 5.4
CVE-2022-23068
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name f…
Tooljet
after 1.10.2
MEDIUM 6.6
CVE-2022-22975
An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would inv…
Pinniped
0.17.0+
HIGH 7.2
CVE-2022-29171
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserv…
Sourcegraph
3.38.0+
HIGH 8.8
CVE-2022-29166
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing…
Matrix Irc Bridge
0.33.2+
HIGH 8.8
CVE-2022-23064
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password …
Snipe It
after 5.3.7
HIGH 7.5
CVE-2022-27924 KEVEPSS 85%
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. Thes…
Zimbra Collaboration Suite
Mitigation only
HIGH 7.2
CVE-2022-20693
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against a…
Ios Xe
Mitigation only
HIGH 7.5
CVE-2022-28345
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking spa…
Signal
5.34+
MEDIUM 6.8
CVE-2022-24832
GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly esc…
Gocd
22.1.0+
CRITICAL 9.8
CVE-2022-24838EPSS 33%
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and …
Calendar
3.2.2+
MEDIUM 5.3
CVE-2021-22055
The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious …
Photon Os
2022-02-16+
CRITICAL 9.8
CVE-2022-1287
A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classe…
School Club Application System
Mitigation only
MEDIUM 5.4
CVE-2022-1074
A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of …
Flex 1085 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-25420
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary …
Goo Blog
No fix yet
CRITICAL 9.8
CVE-2022-26205
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability …
Marky
Mitigation only
HIGH 7.8
CVE-2022-20001
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-re…
Fedora
after 3.3.1
MEDIUM 6.1
CVE-2022-22344
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST…
Spectrum Copy Data Management
2.2.15.0+
CRITICAL 10.0
CVE-2022-24760EPSS 49%
Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Ser…
Parse Server
4.10.7+
HIGH 8.8
CVE-2021-41282EPSS 87%
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the fire…
Pfsense
No fix yet
MEDIUM 5.3
CVE-2022-23701
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior…
Integrated Lights Out
2.60+