Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Wsr 3200ax4s Firmware MEDIUM 6.8
CVE-2022-43486

Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug…

Fix: after 1.26
Fix from $1,600 2022-12-19
Editor.js MEDIUM 6.1
CVE-2022-23474

Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML…

Fix: 2.26.0+
Fix from $1,600 2022-12-15
Seacms CRITICAL 9.8
CVE-2021-39426

An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter whe…

No fix yet
Fix from $2,300 2022-12-15
TYPO3 HIGH 8.8
CVE-2022-23503

TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Cod…

Fix: 8.7.49 / 9.5.38+
Fix from $1,950 2022-12-14
Spip HIGH 8.8
CVE-2022-37155EPSS 40%

RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

Fix: after 4.1.2
Fix from $1,950 2022-12-14
Terminal HIGH 7.8
CVE-2022-44702

Windows Terminal Remote Code Execution Vulnerability

Fix: 1.15.2874+
Fix from $1,950 2022-12-13
Php Calendar MEDIUM 6.1
CVE-2022-4455

A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of th…

Fix: 2022-04-28+
Fix from $1,600 2022-12-13
Pgadmin 4 HIGH 8.8
CVE-2022-4223EPSS 80%

The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_d…

Fix: 6.17+
Fix from $1,950 2022-12-13
Basis HIGH 8.8
CVE-2022-41264

Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allow…

Mitigation only
Fix from $1,950 2022-12-13
Edgeconnect Enterprise HIGH 7.2
CVE-2022-44533

A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the under…

Fix: after 9.2.1.0
Fix from $1,950 2022-12-12
Edgeconnect Enterprise HIGH 7.2
CVE-2022-43541

Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlyi…

Fix: after 9.2.1.0
Fix from $1,950 2022-12-12
Edgeconnect Enterprise HIGH 8.8
CVE-2022-43542

Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlyi…

Fix: after 9.2.1.0
Fix from $1,950 2022-12-12
Z1 All In One G3 Firmware HIGH 8.4
CVE-2021-3661

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is…

Mitigation only
Fix from $1,950 2022-12-12
Spring Boot Admin CRITICAL 9.8
CVE-2022-46166

Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Se…

Fix: 2.6.10 / 2.7.8+
Fix from $2,300 2022-12-09
Product Information Management HIGH 8.8
CVE-2022-46157

Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote au…

Fix: 5.0.119 / 6.0.53+
Fix from $1,950 2022-12-09
Ayacms CRITICAL 9.8
CVE-2022-45550

AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).

No fix yet
Fix from $2,300 2022-12-07
Paddlepaddle CRITICAL 9.8
CVE-2022-46742

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.

Patch available
Fix from $2,300 2022-12-07
Movable Type HIGH 7.2
CVE-2022-43660

Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege …

Fix: 7.9.6+
Fix from $1,950 2022-12-07
Easy Wp Smtp HIGH 8.8
CVE-2022-42699

Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

Fix: after 1.5.1
Fix from $1,950 2022-12-06
Enterprise Protection HIGH 7.2
CVE-2022-46333

The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute co…

Fix: after 8.19.0
Fix from $1,950 2022-12-06
Pdfmake CRITICAL 9.8
CVE-2022-46161

pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evalua…

Fix: after 0.2.5
Fix from $2,300 2022-12-06
Fastcms HIGH 8.8
CVE-2022-4300

A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the com…

No fix yet
Fix from $1,950 2022-12-06
Swiftterm HIGH 7.8
CVE-2022-23465

SwiftTerm is a Xterm/VT100 Terminal emulator. Prior to commit a94e6b24d24ce9680ad79884992e1dff8e150a31, an attacker could modify the window title via…

Fix: 2022-12-02+
Fix from $1,950 2022-12-02
Tvox CRITICAL 9.8
CVE-2022-43333

Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_cont…

Fix: 22.0.17+
Fix from $2,300 2022-12-01
Xg Firewall Firmware HIGH 7.2
CVE-2022-3696

A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.

Fix: after 19.0
Fix from $1,950 2022-12-01
Xg Firewall Firmware HIGH 8.8
CVE-2022-3713

A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 G…

Fix: after 19.0
Fix from $1,950 2022-12-01
Ff4j CRITICAL 9.8
CVE-2022-44262

ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

No fix yet
Fix from $2,300 2022-12-01
Ultimate Member HIGH 7.2
CVE-2022-3384

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_opt…

Fix: after 2.5.0
Fix from $1,950 2022-11-29
Ultimate Member HIGH 7.2
CVE-2022-3383

The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from…

Fix: after 2.5.0
Fix from $1,950 2022-11-29
Xsourceplayer 777d Firmware CRITICAL 9.8
CVE-2022-44038

Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.

No fix yet
Fix from $2,300 2022-11-29