Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X MEDIUM 5.5
CVE-2022-22674 KEV

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fix…

Fix: 10.15.7 / 11.6.6+
Fix from $1,600 2022-05-26
Ios Xr MEDIUM 6.5
CVE-2022-20821 KEVEPSS 12%

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is…

Mitigation only
Fix from $1,600 2022-05-26
Sv Cpt Mc310 Firmware CRITICAL 9.8
CVE-2022-29303 KEVEPSS 98%

SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

Mitigation only
Fix from $2,300 2022-05-12
Usg Flex 100w Firmware CRITICAL 9.8
CVE-2022-30525 KEVEPSS 100%

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware v…

Fix: 5.30+
Fix from $2,300 2022-05-12
Windows 10 1507 MEDIUM 5.9
CVE-2022-26925 KEVEPSS 11%

Windows LSA Spoofing Vulnerability

Fix: 10.0.10240.19297 / 10.0.14393.5125+
Fix from $1,600 2022-05-10
Windows 10 1507 HIGH 8.8
CVE-2022-26923 KEVEPSS 83%

Active Directory Domain Services Elevation of Privilege Vulnerability

Fix: 10.0.10240.19297 / 10.0.14393.5850+
Fix from $1,950 2022-05-10
Debian Linux HIGH 7.5
CVE-2022-30333 KEVEPSS 99%

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …

Fix: 6.12+
Fix from $1,950 2022-05-09
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2022-1388 KEVEPSS 100%

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…

Fix: 13.1.5 / 14.1.4.6+
Fix from $2,300 2022-05-05
Couchdb CRITICAL 9.8
CVE-2022-24706 KEVEPSS 92%

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.…

Fix: 3.2.2+
Fix from $2,300 2022-04-26
Mivoice Connect CRITICAL 9.8
CVE-2022-29499 KEVEPSS 55%

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Serv…

Fix: after 22.20.2300.0
Fix from $2,300 2022-04-26
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2022-27926 KEVEPSS 18%

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauth…

Mitigation only
Fix from $1,600 2022-04-21
Zimbra Collaboration Suite HIGH 7.2
CVE-2022-27925 KEVEPSS 99%

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated u…

Mitigation only
Fix from $1,950 2022-04-21
Zimbra Collaboration Suite HIGH 7.5
CVE-2022-27924 KEVEPSS 85%

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. Thes…

Mitigation only
Fix from $1,950 2022-04-21
Application Development Framework CRITICAL 9.8
CVE-2022-21445 KEVEPSS 62%

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t…

Mitigation only
Fix from $2,300 2022-04-19
Api Manager CRITICAL 9.8
CVE-2022-29464 KEVEPSS 100%

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Conten…

Fix: after 6.6.0
Fix from $2,300 2022-04-18
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2022-28810 KEVEPSS 71%

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST…

Fix: 6.1+
Fix from $1,600 2022-04-18
Windows 10 1507 HIGH 7.0
CVE-2022-26904 KEVEPSS 10%

Windows User Profile Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19265 / 10.0.14393.5066+
Fix from $1,950 2022-04-15
Windows 10 1507 HIGH 7.8
CVE-2022-24521 KEVEPSS 7%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.19265 / 10.0.14393.5066+
Fix from $1,950 2022-04-15
Jai Ext CRITICAL 10.0
CVE-2022-24816 KEVEPSS 99%

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via networ…

Fix: 1.1.22+
Fix from $2,300 2022-04-13
Cloud Foundation HIGH 7.8
CVE-2022-22960 KEVEPSS 36%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13
Identity Manager CRITICAL 9.8
CVE-2022-22954 KEVEPSS 100%

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious act…

Fix: after 8.2
Fix from $2,300 2022-04-11
Chrome HIGH 8.8
CVE-2022-0609 KEVEPSS 21%

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 98.0.4758.102+
Fix from $1,950 2022-04-05
Spring Framework CRITICAL 9.8
CVE-2022-22965 KEVEPSS 100%

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit …

Fix: 2.1.0 / 5.2.20+
Fix from $2,300 2022-04-01
Spring Cloud Function CRITICAL 9.8
CVE-2022-22963 KEVEPSS 100%

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide …

Fix: after 3.2.2
Fix from $2,300 2022-04-01
Apex Central CRITICAL 9.8
CVE-2022-26871 KEVEPSS 20%

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which c…

Patch available
Fix from $2,300 2022-03-29
Cloud Foundation MEDIUM 6.5
CVE-2022-22948 KEVEPSS 13%

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac…

Fix: 3.11 / 4.4.1+
Fix from $1,600 2022-03-29
Dir 820l Firmware CRITICAL 9.8
CVE-2022-26258 KEVEPSS 80%

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

Mitigation only
Fix from $2,300 2022-03-28
Sfos CRITICAL 9.8
CVE-2022-1040 KEVEPSS 100%

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 …

Fix: after 18.5.3
Fix from $2,300 2022-03-25
Safari HIGH 8.8
CVE-2022-22620 KEVEPSS 16%

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Saf…

Fix: 12.2.1 / 15.3+
Fix from $1,950 2022-03-18
Ipados CRITICAL 9.8
CVE-2022-22587 KEVEPSS 12%

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS …

Fix: 11.6.3 / 12.2+
Fix from $2,300 2022-03-18