Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
CRITICAL 9.8 CVE-2021-26729 Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker t… Iac Ast2500a Firmware Mitigation only Fix from $2,3002022-10-24 CRITICAL 9.8 CVE-2021-26731 Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticate… Iac Ast2500a Firmware Mitigation only Fix from $2,3002022-10-24 HIGH 8.8 CVE-2022-43416 Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be executed and allows invoking Kat… Katalon 1.0.33+ Fix from $1,9502022-10-19 HIGH 8.1 CVE-2022-39424 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4… Vm Virtualbox 6.1.40+ Fix from $1,9502022-10-18 CRITICAL 9.8 CVE-2022-41544EPSS 10% GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php. Getsimple Cms No fix yet Fix from $2,3002022-10-18 HIGH 7.8 CVE-2022-41576 The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be i… Emui No fix yet Fix from $1,9502022-10-14 HIGH 7.2 CVE-2022-35944 October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations t… October 2.2.34 / 3.0.66+ Fix from $1,9502022-10-13 HIGH 7.2 CVE-2022-41534 Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrd… Online Diagnostic Lab Management System No fix yet Fix from $1,9502022-10-13 CRITICAL 9.8 CVE-2022-42889EPSS 100% Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat… Commons Text 1.10.0 / 7.5.0+ Fix from $2,3002022-10-13 HIGH 8.8 CVE-2022-42902 In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input… Debian Linux 2022.10+ Fix from $1,9502022-10-13 CRITICAL 9.8 CVE-2022-40871EPSS 33% Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if … Dolibarr Erp\/crm after 15.0.3 Fix from $2,3002022-10-12 HIGH 8.8 CVE-2022-40469 iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability. Ikuaios 3.6.8+ Fix from $1,9502022-10-12 HIGH 7.8 CVE-2022-40274 Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file throug… Gridea No fix yet Fix from $1,9502022-09-30 HIGH 8.8 CVE-2022-40486 TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary co… Archer Ax10 V1 Firmware No fix yet Fix from $1,9502022-09-28 HIGH 8.8 CVE-2022-40497 Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability vi… Wazuh after 4.3.7 Fix from $1,9502022-09-28 CRITICAL 9.8 CVE-2022-21797 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval()… Joblib 1.1.1+ Fix from $2,3002022-09-26 CRITICAL 9.8 CVE-2022-40628 This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive),… En6200 Prime Quad 35 Firmware 22.21.2+ Fix from $2,3002022-09-23 CRITICAL 9.8 CVE-2022-3236 KEVEPSS 99% A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and olde… Firewall after 19.0.1 Fix from $2,3002022-09-23 CRITICAL 9.8 CVE-2022-26112 In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to… Pinot 0.11.0+ Fix from $2,3002022-09-23 HIGH 7.2 CVE-2022-36386 Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. Wp All Import after 3.6.7 Fix from $1,9502022-09-21 HIGH 8.8 CVE-2022-28640 A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availabili… Integrated Lights Out 5 Firmware 2.72+ Fix from $1,9502022-09-20 CRITICAL 9.8 CVE-2022-41138 In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution. Zutty 0.13+ Fix from $2,3002022-09-20 MEDIUM 6.1 CVE-2022-3245 HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, inject… Microweber 1.3.2+ Fix from $1,6002022-09-20 MEDIUM 6.1 CVE-2022-3242 Code Injection in GitHub repository microweber/microweber prior to 1.3.2. Microweber 1.3.2+ Fix from $1,6002022-09-20 HIGH 8.8 CVE-2022-36099EPSS 76% XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 … Xwiki 13.10.6 / 14.4+ Fix from $1,9502022-09-08 HIGH 8.8 CVE-2022-36100EPSS 74% XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki… Xwiki 13.10.6 / 14.4+ Fix from $1,9502022-09-08 HIGH 7.3 CVE-2022-36069 Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various comm… Poetry 1.1.9+ Fix from $1,9502022-09-07 CRITICAL 9.8 CVE-2022-31860 An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule. Openremote after 1.0.4 Fix from $2,3002022-09-06 HIGH 8.8 CVE-2022-35847 An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 thro… Fortisoar after 7.0.3 Fix from $1,9502022-09-06 HIGH 7.5 CVE-2022-25813EPSS 67% In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a … Ofbiz 18.12.06+ Fix from $1,9502022-09-02