Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.7
CVE-2022-29814
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
Intellij Idea
2022.1+
MEDIUM 6.7
CVE-2022-29815
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
Intellij Idea
2022.1+
HIGH 7.7
CVE-2022-29819
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
Intellij Idea
2022.1+
HIGH 7.7
CVE-2022-29821
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
Pycharm
2022.1+
HIGH 7.8
CVE-2022-24735
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Re…
Redis
6.2.7+
CRITICAL 9.8
CVE-2022-24881
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote…
Codegen
1.0.0+
CRITICAL 9.8
CVE-2022-29078EPSS 33%
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionN…
Ejs
Patch available
HIGH 7.2
CVE-2022-0661EPSS 40%
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privil…
Ad Injection
after 1.2.0.19
CRITICAL 10.0
CVE-2022-24816 KEVEPSS 99%
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via networ…
Jai Ext
1.1.22+
HIGH 7.8
CVE-2022-27837
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to …
Accessibility
12.5.3.2 / 13.0.1.1+
CRITICAL 9.8
CVE-2022-22954 KEVEPSS 100%
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act…
Identity Manager
after 8.2
HIGH 8.8
CVE-2021-40219
Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side t…
Bolt Cms
after 4.2.0
HIGH 8.8
CVE-2022-24780EPSS 5%
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the…
Itop
2.7.6+
HIGH 7.2
CVE-2022-26982EPSS 9%
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because…
Simple Machines Forum
after 2.1.1
HIGH 8.8
CVE-2021-39114
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arb…
Confluence Data Center
6.13.23 / 7.4.11+
CRITICAL 9.8
CVE-2022-22963 KEVEPSS 100%
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide …
Spring Cloud Function
after 3.2.2
CRITICAL 9.8
CVE-2022-22965 KEVEPSS 100%
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit …
Spring Framework
2.1.0 / 5.2.20+
HIGH 7.2
CVE-2022-1159
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation runn…
Controllogix 5580 Firmware
Mitigation only
HIGH 7.5
CVE-2021-39908
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4…
GitLab
14.2.6 / 14.3.4+
HIGH 7.2
CVE-2021-43097
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrar…
Bbs
No fix yet
CRITICAL 10.0
CVE-2021-26622
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote…
Genian Nac
after 5.0.42.0827
MEDIUM 6.8
CVE-2021-38745
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a craft…
Chamilo
Patch available
CRITICAL 9.8
CVE-2021-39383
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
Dwsurvey
No fix yet
CRITICAL 9.8
CVE-2022-25578
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
Taocms
Mitigation only
HIGH 8.8
CVE-2020-25197
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A0…
Rt430 Firmware
08a06+
CRITICAL 9.8
CVE-2020-15591
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).
Frams\' Fast File Exchange
20160919_2+
CRITICAL 9.8
CVE-2022-25760
All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization.…
Accesslog
No fix yet
HIGH 8.8
CVE-2022-0811EPSS 19%
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster th…
Cri O
1.19.6 / 1.20.7+
CRITICAL 9.8
CVE-2022-25498
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
Cuppacms
No fix yet
HIGH 7.2
CVE-2022-0944EPSS 9%
Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.
Sqlpad
6.10.1+