Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.8 CVE-2022-43486 Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug… Wsr 3200ax4s Firmware after 1.26 Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2022-23474 Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML… Editor.js 2.26.0+ Fix from $1,6002022-12-15 CRITICAL 9.8 CVE-2021-39426 An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter whe… Seacms No fix yet Fix from $2,3002022-12-15 HIGH 8.8 CVE-2022-23503 TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Cod… TYPO3 8.7.49 / 9.5.38+ Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-37155EPSS 40% RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. Spip after 4.1.2 Fix from $1,9502022-12-14 HIGH 7.8 CVE-2022-44702 Windows Terminal Remote Code Execution Vulnerability Terminal 1.15.2874+ Fix from $1,9502022-12-13 MEDIUM 6.1 CVE-2022-4455 A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of th… Php Calendar 2022-04-28+ Fix from $1,6002022-12-13 HIGH 8.8 CVE-2022-4223EPSS 80% The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_d… Pgadmin 4 6.17+ Fix from $1,9502022-12-13 HIGH 8.8 CVE-2022-41264 Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allow… Basis Mitigation only Fix from $1,9502022-12-13 HIGH 7.2 CVE-2022-44533 A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the under… Edgeconnect Enterprise after 9.2.1.0 Fix from $1,9502022-12-12 HIGH 7.2 CVE-2022-43541 Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlyi… Edgeconnect Enterprise after 9.2.1.0 Fix from $1,9502022-12-12 HIGH 8.8 CVE-2022-43542 Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlyi… Edgeconnect Enterprise after 9.2.1.0 Fix from $1,9502022-12-12 HIGH 8.4 CVE-2021-3661 A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is… Z1 All In One G3 Firmware Mitigation only Fix from $1,9502022-12-12 CRITICAL 9.8 CVE-2022-46166 Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Se… Spring Boot Admin 2.6.10 / 2.7.8+ Fix from $2,3002022-12-09 HIGH 8.8 CVE-2022-46157 Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote au… Product Information Management 5.0.119 / 6.0.53+ Fix from $1,9502022-12-09 CRITICAL 9.8 CVE-2022-45550 AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE). Ayacms No fix yet Fix from $2,3002022-12-07 CRITICAL 9.8 CVE-2022-46742 Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. Paddlepaddle Patch available Fix from $2,3002022-12-07 HIGH 7.2 CVE-2022-43660 Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege … Movable Type 7.9.6+ Fix from $1,9502022-12-07 HIGH 8.8 CVE-2022-42699 Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. Easy Wp Smtp after 1.5.1 Fix from $1,9502022-12-06 HIGH 7.2 CVE-2022-46333 The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute co… Enterprise Protection after 8.19.0 Fix from $1,9502022-12-06 CRITICAL 9.8 CVE-2022-46161 pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evalua… Pdfmake after 0.2.5 Fix from $2,3002022-12-06 HIGH 8.8 CVE-2022-4300 A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the com… Fastcms No fix yet Fix from $1,9502022-12-06 HIGH 7.8 CVE-2022-23465 SwiftTerm is a Xterm/VT100 Terminal emulator. Prior to commit a94e6b24d24ce9680ad79884992e1dff8e150a31, an attacker could modify the window title via… Swiftterm 2022-12-02+ Fix from $1,9502022-12-02 CRITICAL 9.8 CVE-2022-43333 Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_cont… Tvox 22.0.17+ Fix from $2,3002022-12-01 HIGH 7.2 CVE-2022-3696 A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA. Xg Firewall Firmware after 19.0 Fix from $1,9502022-12-01 HIGH 8.8 CVE-2022-3713 A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 G… Xg Firewall Firmware after 19.0 Fix from $1,9502022-12-01 CRITICAL 9.8 CVE-2022-44262 ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE). Ff4j No fix yet Fix from $2,3002022-12-01 HIGH 7.2 CVE-2022-3384 The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_opt… Ultimate Member after 2.5.0 Fix from $1,9502022-11-29 HIGH 7.2 CVE-2022-3383 The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from… Ultimate Member after 2.5.0 Fix from $1,9502022-11-29 CRITICAL 9.8 CVE-2022-44038 Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component. Xsourceplayer 777d Firmware No fix yet Fix from $2,3002022-11-29