Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-26729
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker t…
Iac Ast2500a Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-26731
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticate…
Iac Ast2500a Firmware
Mitigation only
HIGH 8.8
CVE-2022-43416
Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be executed and allows invoking Kat…
Katalon
1.0.33+
HIGH 8.1
CVE-2022-39424
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4…
Vm Virtualbox
6.1.40+
CRITICAL 9.8
CVE-2022-41544EPSS 10%
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.
Getsimple Cms
No fix yet
HIGH 7.8
CVE-2022-41576
The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be i…
Emui
No fix yet
HIGH 7.2
CVE-2022-35944
October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations t…
October
2.2.34 / 3.0.66+
HIGH 7.2
CVE-2022-41534
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrd…
Online Diagnostic Lab Management System
No fix yet
CRITICAL 9.8
CVE-2022-42889EPSS 100%
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolat…
Commons Text
1.10.0 / 7.5.0+
HIGH 8.8
CVE-2022-42902
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input…
Debian Linux
2022.10+
CRITICAL 9.8
CVE-2022-40871EPSS 33%
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if …
Dolibarr Erp\/crm
after 15.0.3
HIGH 8.8
CVE-2022-40469
iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
Ikuaios
3.6.8+
HIGH 7.8
CVE-2022-40274
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file throug…
Gridea
No fix yet
HIGH 8.8
CVE-2022-40486
TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary co…
Archer Ax10 V1 Firmware
No fix yet
HIGH 8.8
CVE-2022-40497
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability vi…
Wazuh
after 4.3.7
CRITICAL 9.8
CVE-2022-21797
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval()…
Joblib
1.1.1+
CRITICAL 9.8
CVE-2022-40628
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive),…
En6200 Prime Quad 35 Firmware
22.21.2+
CRITICAL 9.8
CVE-2022-3236 KEVEPSS 99%
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and olde…
Firewall
after 19.0.1
CRITICAL 9.8
CVE-2022-26112
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to…
Pinot
0.11.0+
HIGH 7.2
CVE-2022-36386
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
Wp All Import
after 3.6.7
HIGH 8.8
CVE-2022-28640
A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availabili…
Integrated Lights Out 5 Firmware
2.72+
CRITICAL 9.8
CVE-2022-41138
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
Zutty
0.13+
MEDIUM 6.1
CVE-2022-3245
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, inject…
Microweber
1.3.2+
MEDIUM 6.1
CVE-2022-3242
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
Microweber
1.3.2+
HIGH 8.8
CVE-2022-36099EPSS 76%
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 …
Xwiki
13.10.6 / 14.4+
HIGH 8.8
CVE-2022-36100EPSS 74%
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki…
Xwiki
13.10.6 / 14.4+
HIGH 7.3
CVE-2022-36069
Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various comm…
Poetry
1.1.9+
CRITICAL 9.8
CVE-2022-31860
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
Openremote
after 1.0.4
HIGH 8.8
CVE-2022-35847
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 thro…
Fortisoar
after 7.0.3
HIGH 7.5
CVE-2022-25813EPSS 67%
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a …
Ofbiz
18.12.06+