Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2022-26485 KEVEPSS 14%

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing thi…

Fix: 91.6.1 / 91.6.2+
Fix from $1,950 2022-12-22
Safari HIGH 8.8
CVE-2022-42856 KEVEPSS 9%

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and …

Fix: 13.1 / 15.7.2+
Fix from $1,950 2022-12-15
Windows 10 1607 MEDIUM 5.4
CVE-2022-44698 KEVEPSS 76%

Windows SmartScreen Security Feature Bypass Vulnerability

Fix: 10.0.14393.5582 / 10.0.17763.3770+
Fix from $1,600 2022-12-13
Application Delivery Controller Firmware CRITICAL 9.8
CVE-2022-27518 KEVEPSS 7%

Unauthenticated remote arbitrary code execution

Fix: 12.1-55.291 / 12.1-65.25+
Fix from $2,300 2022-12-13
Cacti CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …

Fix: 1.2.23+
Fix from $2,300 2022-12-05
Chrome HIGH 8.8
CVE-2022-4262 KEVEPSS 15%

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 108.0.5359.94+
Fix from $1,950 2022-12-02
Dnr 322l Firmware HIGH 8.8
CVE-2022-40799 KEVEPSS 32%

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

Fix: after 2.60b15
Fix from $1,950 2022-11-29
Chrome CRITICAL 9.6
CVE-2022-4135 KEVEPSS 32%

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 107.0.1418.62 / 107.0.5304.121+
Fix from $2,300 2022-11-25
Mivoice Connect MEDIUM 6.8
CVE-2022-41223 KEVEPSS 11%

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection atta…

Fix: after 22.22.6100.0
Fix from $1,600 2022-11-22
Mivoice Connect MEDIUM 6.8
CVE-2022-40765 KEVEPSS 10%

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with interna…

Fix: after 22.22.6100.0
Fix from $1,600 2022-11-22
Dante Application Library HIGH 7.8
CVE-2022-23748 KEVEPSS 9%

mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what cond…

Fix: after 1.2.0
Fix from $1,950 2022-11-17
Windows 10 1507 HIGH 8.8
CVE-2022-41128 KEVEPSS 25%

Windows Scripting Languages Remote Code Execution Vulnerability

Fix: 10.0.10240.19567 / 10.0.14393.5501+
Fix from $1,950 2022-11-09
Windows 10 1507 HIGH 7.8
CVE-2022-41125 KEV

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19567 / 10.0.14393.5501+
Fix from $1,950 2022-11-09
Windows 10 1507 MEDIUM 5.4
CVE-2022-41091 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Fix: 10.0.10240.19567 / 10.0.14393.5501+
Fix from $1,600 2022-11-09
Exchange Server HIGH 8.8
CVE-2022-41080 KEVEPSS 77%

Microsoft Exchange Server Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2022-11-09
Windows 10 1507 HIGH 7.8
CVE-2022-41073 KEV

Windows Print Spooler Elevation of Privilege Vulnerability

Fix: 10.0.10240.19567 / 10.0.14393.5501+
Fix from $1,950 2022-11-09
Windows 10 1507 MEDIUM 5.4
CVE-2022-41049 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Fix: 10.0.10240.19567 / 10.0.14393.5501+
Fix from $1,600 2022-11-09
Auditor CRITICAL 9.8
CVE-2022-31199 KEVEPSS 36%

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server …

Fix: 10.5+
Fix from $2,300 2022-11-08
Chrome HIGH 8.8
CVE-2022-3723 KEVEPSS 8%

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 107.0.5304.87+
Fix from $1,950 2022-11-01
Ipados HIGH 7.8
CVE-2022-42827 KEV

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16…

Fix: 15.7.1 / 16.1+
Fix from $1,950 2022-11-01
Bifrost Gpu Kernel Driver HIGH 8.8
CVE-2022-38181 KEVEPSS 13%

The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0…

Mitigation only
Fix from $1,950 2022-10-25
Dsl 2750b Firmware CRITICAL 9.8
CVE-2016-20017 KEVEPSS 65%

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016…

Fix: 1.05+
Fix from $2,300 2022-10-19
E Business Suite CRITICAL 9.8
CVE-2022-21587 KEVEPSS 98%

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are a…

Fix: after 12.2.11
Fix from $2,300 2022-10-18
Fortiproxy CRITICAL 9.8
CVE-2022-40684 KEVEPSS 100%

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiP…

Fix: 7.0.7 / 7.2.2+
Fix from $2,300 2022-10-18
Windows 10 1507 HIGH 7.8
CVE-2022-41033 KEV

Windows COM+ Event System Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19507 / 10.0.14393.5427+
Fix from $1,950 2022-10-11
Windows 10 1507 HIGH 7.8
CVE-2022-38028 KEVEPSS 15%

Windows Print Spooler Elevation of Privilege Vulnerability

Fix: 6.3.9600.20625 / 10.0.10240.19507+
Fix from $1,950 2022-10-11
Exchange Server HIGH 8.0
CVE-2022-41082 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2022-10-03
Exchange Server HIGH 8.8
CVE-2022-41040 KEVEPSS 100%

Microsoft Exchange Server Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2022-10-03
Catalyst Sd Wan Manager HIGH 7.8
CVE-2022-20775 KEVEPSS 12%

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability i…

Fix: 20.6.3 / 20.7.2+
Fix from $1,950 2022-09-30
Chrome CRITICAL 9.6
CVE-2022-3075 KEVEPSS 6%

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to p…

Fix: 105.0.5195.102+
Fix from $2,300 2022-09-26