Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Veeam Backup \& Replication CRITICAL 9.8
CVE-2022-26501 KEV

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

Fix: 10.0.1.4854 / 11.0.1.1261+
Fix from $2,300 2022-03-17
Veeam Backup \& Replication HIGH 8.8
CVE-2022-26500 KEVEPSS 6%

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API …

Fix: 10.0.1.4854 / 11.0.1.1261+
Fix from $1,950 2022-03-17
Android HIGH 7.8
CVE-2021-39793 KEV

In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to loca…

Mitigation only
Fix from $1,950 2022-03-16
Micollab CRITICAL 9.8
CVE-2022-26143 KEVEPSS 87%

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain s…

Fix: 9.4+
Fix from $2,300 2022-03-10
Linux Kernel HIGH 7.8
CVE-2022-0847 KEVEPSS 89%

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_…

Fix: 5.10.102 / 5.15.25+
Fix from $1,950 2022-03-10
Fireware CRITICAL 9.8
CVE-2022-26318 KEVEPSS 78%

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS b…

Fix: 12.1.3 / 12.5.9+
Fix from $2,300 2022-03-04
Spring Cloud Gateway CRITICAL 10.0
CVE-2022-22947 KEVEPSS 98%

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi…

Fix: 3.0.7+
Fix from $2,300 2022-03-03
Linux Kernel HIGH 7.8
CVE-2022-0492 KEVEPSS 6%

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circum…

Fix: 4.9.301 / 4.14.266+
Fix from $1,950 2022-03-03
Bifrost Gpu Kernel Driver HIGH 7.8
CVE-2022-22706 KEV

Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, …

Mitigation only
Fix from $1,950 2022-03-03
Fireware HIGH 8.8
CVE-2022-23176 KEVEPSS 13%

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session…

Fix: 12.1.3 / 12.5.7+
Fix from $1,950 2022-02-24
Redis CRITICAL 10.0
CVE-2022-0543 KEVEPSS 99%

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which c…

Patch available
Fix from $2,300 2022-02-18
Dir 820l Firmware CRITICAL 9.8
CVE-2021-45382 KEVEPSS 98%

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L rout…

Mitigation only
Fix from $2,300 2022-02-17
Debian Linux HIGH 7.8
CVE-2021-3560 KEVEPSS 22%

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r…

Fix: 0.119+
Fix from $1,950 2022-02-16
Commerce CRITICAL 9.8
CVE-2022-24086 KEVEPSS 99%

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the check…

Fix: 2.3.0+
Fix from $2,300 2022-02-16
Chrome HIGH 8.8
CVE-2021-4102 KEVEPSS 8%

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 96.0.4664.110+
Fix from $1,950 2022-02-11
Linux Kernel HIGH 8.4
CVE-2022-0185 KEVEPSS 25%

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel ve…

Fix: 5.4.173 / 5.10.93+
Fix from $1,950 2022-02-11
Apisix CRITICAL 9.8
CVE-2022-24112 KEVEPSS 96%

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX …

Fix: 2.10.4 / 2.12.1+
Fix from $2,300 2022-02-11
Rv340 Firmware HIGH 8.0
CVE-2022-20708 KEVEPSS 15%

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…

Fix: after 1.0.03.24
Fix from $1,950 2022-02-10
Rv340 Firmware HIGH 8.0
CVE-2022-20703 KEVEPSS 9%

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…

Fix: after 1.0.03.24
Fix from $1,950 2022-02-10
Rv340 Firmware HIGH 7.8
CVE-2022-20701 KEVEPSS 10%

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…

Fix: after 1.0.03.24
Fix from $1,950 2022-02-10
Rv340 Firmware CRITICAL 9.8
CVE-2022-20700 KEVEPSS 6%

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…

Fix: after 1.0.03.24
Fix from $2,300 2022-02-10
Rv340 Firmware CRITICAL 9.8
CVE-2022-20699 KEVEPSS 72%

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…

Fix: after 1.0.03.24
Fix from $2,300 2022-02-10
Content Server CRITICAL 10.0
CVE-2022-22536 KEVEPSS 98%

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulne…

Mitigation only
Fix from $2,300 2022-02-09
Windows 10 1507 HIGH 7.8
CVE-2022-22718 KEVEPSS 18%

Windows Print Spooler Elevation of Privilege Vulnerability

Fix: 10.0.10240.19204 / 10.0.14393.4946+
Fix from $1,950 2022-02-09
Windows 10 1507 HIGH 7.8
CVE-2022-21999 KEVEPSS 42%

Windows Print Spooler Elevation of Privilege Vulnerability

Fix: 10.0.10240.19204 / 10.0.14393.4946+
Fix from $1,950 2022-02-09
Windows 10 1809 HIGH 7.8
CVE-2022-21971 KEVEPSS 54%

Windows Runtime Remote Code Execution Vulnerability

Fix: 10.0.17763.2565 / 10.0.18363.2094+
Fix from $1,950 2022-02-09
Zimbra Collaboration Suite MEDIUM 6.1
CVE-2022-24682 KEVEPSS 31%

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild start…

Fix: 8.8.15+
Fix from $1,600 2022-02-09
Enterprise Linux Server Update Services For Sap Solutions HIGH 7.8
CVE-2021-4034 KEVEPSS 95%

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

Patch available
Fix from $1,950 2022-01-28
Rlc 410w Firmware HIGH 7.2
CVE-2021-40407 KEVEPSS 48%

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas…

Mitigation only
Fix from $1,950 2022-01-28
Linux Kernel HIGH 7.0
CVE-2021-22600 KEVEPSS 6%

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or …

Fix: 4.14.259 / 4.19.222+
Fix from $1,950 2022-01-26