Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2022-45907 In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely. Pytorch 1.13.1+ Fix from $2,3002022-11-26 CRITICAL 9.8 CVE-2022-45908 In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This … Paddlepaddle 2.4+ Fix from $2,3002022-11-26 CRITICAL 9.8 CVE-2022-41158 Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploi… Eyoom Builder after 4.5.3 Fix from $2,3002022-11-25 HIGH 7.2 CVE-2022-39833 FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoint… Filecloud 21.3.7.18607+ Fix from $1,9502022-11-23 MEDIUM 6.8 CVE-2022-41223 KEVEPSS 11% The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection atta… Mivoice Connect after 22.22.6100.0 Fix from $1,6002022-11-22 CRITICAL 9.8 CVE-2022-41945 super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced ​​into the command, resu… Super Xray No fix yet Fix from $2,3002022-11-21 CRITICAL 9.8 CVE-2022-45132 In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. Th… Lava 2022.11.1+ Fix from $2,3002022-11-18 HIGH 7.3 CVE-2022-28766 Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a D… Meetings 5.12.6+ Fix from $1,9502022-11-17 HIGH 7.2 CVE-2022-43279 LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php. Limesurvey Patch available Fix from $1,9502022-11-15 HIGH 8.8 CVE-2022-40127EPSS 86% A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually … Airflow 2.4.0+ Fix from $1,9502022-11-14 HIGH 7.8 CVE-2022-41882 The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, if a user received a maliciou… Desktop Patch available Fix from $1,9502022-11-11 CRITICAL 9.8 CVE-2022-44087 ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT. Espcms Mitigation only Fix from $2,3002022-11-10 CRITICAL 9.8 CVE-2022-44088EPSS 20% ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. Espcms Mitigation only Fix from $2,3002022-11-10 CRITICAL 9.8 CVE-2022-44089 ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE. Espcms Mitigation only Fix from $2,3002022-11-10 HIGH 7.8 CVE-2022-41061 Microsoft Word Remote Code Execution Vulnerability 365 Apps No fix yet Fix from $1,9502022-11-09 MEDIUM 6.1 CVE-2022-41205 SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registr… Gui Mitigation only Fix from $1,6002022-11-08 HIGH 7.2 CVE-2022-3418 The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the ser… Wp All Import 3.6.9+ Fix from $1,9502022-11-07 HIGH 8.8 CVE-2022-44794 An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrar… Ootbi 1.0.13.1611+ Fix from $1,9502022-11-07 MEDIUM 6.1 CVE-2022-3869 Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2. Froxlor 0.10.38.2+ Fix from $1,6002022-11-05 MEDIUM 6.5 CVE-2022-43572 In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HE… Splunk 8.1.12 / 8.2.9+ Fix from $1,6002022-11-04 CRITICAL 9.8 CVE-2022-31691 Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor… Bosh Editor 1.40.0 / 4.16.1+ Fix from $2,3002022-11-04 HIGH 8.8 CVE-2022-43571EPSS 13% In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation c… Splunk 8.1.12 / 8.2.9+ Fix from $1,9502022-11-03 HIGH 7.8 CVE-2022-32924 The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 … Ipados 9.1 / 11.7+ Fix from $1,9502022-11-01 CRITICAL 9.8 CVE-2020-21016 D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php. Dir 846 Firmware No fix yet Fix from $2,3002022-10-31 CRITICAL 9.8 CVE-2022-39365 Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/… Pimcore 10.5.9+ Fix from $2,3002022-10-27 HIGH 7.2 CVE-2022-3394 The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allow… Wp All Export 1.7.9+ Fix from $1,9502022-10-25 HIGH 8.8 CVE-2022-39326 kartverket/github-workflows are shared reusable workflows for GitHub Actions. Prior to version 2.7.5, all users of the `run-terraform` reusable workf… Github Workflows 2.7.5+ Fix from $1,9502022-10-25 CRITICAL 9.8 CVE-2022-39327 Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code in… Azure Command Line Interface 2.40.0+ Fix from $2,3002022-10-25 CRITICAL 9.8 CVE-2021-26727 Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker… Iac Ast2500a Firmware Mitigation only Fix from $2,3002022-10-24 CRITICAL 9.8 CVE-2021-26728 Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arb… Iac Ast2500a Firmware Mitigation only Fix from $2,3002022-10-24