Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome HIGH 8.8
CVE-2022-3038 KEVEPSS 25%

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a craf…

Fix: 105.0.5195.52+
Fix from $1,950 2022-09-26
Chrome MEDIUM 6.5
CVE-2022-2856 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily br…

Fix: 104.0.5112.101 / 104.0.5112.102+
Fix from $1,600 2022-09-26
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2022-41352 KEVEPSS 95%

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extr…

Patch available
Fix from $2,300 2022-09-26
Firewall CRITICAL 9.8
CVE-2022-3236 KEVEPSS 99%

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and olde…

Fix: after 19.0.1
Fix from $2,300 2022-09-23
Cobalt Strike MEDIUM 6.1
CVE-2022-39197 KEVEPSS 46%

An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the …

Fix: 4.7.1+
Fix from $1,600 2022-09-22
Ipados HIGH 7.8
CVE-2022-32917 KEVEPSS 6%

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7…

Fix: 11.7 / 12.6+
Fix from $1,950 2022-09-20
Apex One HIGH 7.2
CVE-2022-40139 KEV

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could all…

Patch available
Fix from $1,950 2022-09-19
Glpi CRITICAL 9.8
CVE-2022-35914 KEVEPSS 100%

/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

Fix: after 10.0.2
Fix from $2,300 2022-09-19
Windows 10 1507 HIGH 7.8
CVE-2022-37969 KEVEPSS 28%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.19444 / 10.0.14393.5356+
Fix from $1,950 2022-09-13
Photo Station CRITICAL 9.1
CVE-2022-27593 KEVEPSS 88%

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could a…

Fix: 5.2.14 / 5.4.15+
Fix from $2,300 2022-09-08
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2022-37055 KEVEPSS 56%

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

Patch available
Fix from $2,300 2022-08-28
Zk Framework HIGH 7.5
CVE-2022-36537 KEVEPSS 95%

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the co…

Fix: 8.6.4.2 / 9.0.1.3+
Fix from $1,950 2022-08-26
Bitbucket HIGH 8.8
CVE-2022-36804 KEVEPSS 99%

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from ver…

Fix: 7.6.17 / 7.17.10+
Fix from $1,950 2022-08-25
Ipados HIGH 7.8
CVE-2022-32894 KEV

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1.…

Fix: 9.0 / 11.7+
Fix from $1,950 2022-08-24
Safari HIGH 8.8
CVE-2022-32893 KEVEPSS 10%

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1,…

Fix: 2.36.7 / 12.5.1+
Fix from $1,950 2022-08-24
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2022-37042 KEVEPSS 92%

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing aut…

Patch available
Fix from $2,300 2022-08-12
Pan Os HIGH 8.6
CVE-2022-0028 KEV

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) a…

Fix: 8.1.23 / 9.0.16+
Fix from $1,950 2022-08-10
Windows 10 1507 HIGH 7.8
CVE-2022-34713 KEVEPSS 68%

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Fix: 10.0.10240.19387 / 10.0.14393.5291+
Fix from $1,950 2022-08-09
Chrome HIGH 8.8
CVE-2022-2294 KEVEPSS 70%

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 2.36.5 / 10.15.7+
Fix from $1,950 2022-07-28
Chrome HIGH 8.8
CVE-2022-1364 KEVEPSS 14%

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 100.0.4896.127+
Fix from $1,950 2022-07-26
Chrome HIGH 8.8
CVE-2022-1096 KEVEPSS 24%

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 99.0.4844.84+
Fix from $1,950 2022-07-23
Questions For Confluence CRITICAL 9.8
CVE-2022-26138 KEVEPSS 98%

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with…

Patch available
Fix from $2,300 2022-07-20
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2022-35405 KEVEPSS 100%

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affect…

Fix: 4.3 / 5.5+
Fix from $2,300 2022-07-19
Spark HIGH 8.8
CVE-2022-33891 KEVEPSS 93%

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks …

Fix: after 3.2.1
Fix from $1,950 2022-07-18
Dotcms CRITICAL 9.8
CVE-2022-26352 KEVEPSS 91%

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose fil…

Fix: after 22.02
Fix from $2,300 2022-07-17
Windows 10 1507 HIGH 7.8
CVE-2022-22047 KEVEPSS 17%

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

Fix: 10.0.10240.19360 / 10.0.14393.5246+
Fix from $1,950 2022-07-12
Apq8053 Firmware HIGH 7.8
CVE-2022-22071 KEV

Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snap…

Patch available
Fix from $1,950 2022-06-14
Confluence Data Center CRITICAL 9.8
CVE-2022-26134 KEVEPSS 100%

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exe…

Fix: 7.4.17 / 7.13.7+
Fix from $2,300 2022-06-03
Windows 10 1507 HIGH 7.8
CVE-2022-30190 KEVEPSS 99%

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who succ…

Fix: 10.0.10240.19325 / 10.0.14393.5192+
Fix from $1,950 2022-06-01
Ipados HIGH 7.8
CVE-2022-22675 KEVEPSS 12%

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS …

Fix: 8.6 / 11.6.6+
Fix from $1,950 2022-05-26