Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-26501 KEV Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). Veeam Backup \& Replication 10.0.1.4854 / 11.0.1.1261+ Fix from $2,3002022-03-17 HIGH 8.8 CVE-2022-26500 KEVEPSS 6% Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API … Veeam Backup \& Replication 10.0.1.4854 / 11.0.1.1261+ Fix from $1,9502022-03-17 HIGH 7.8 CVE-2021-39793 KEV In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to loca… Android Mitigation only Fix from $1,9502022-03-16 CRITICAL 9.8 CVE-2022-26143 KEVEPSS 87% The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain s… Micollab 9.4+ Fix from $2,3002022-03-10 HIGH 7.8 CVE-2022-0847 KEVEPSS 89% A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_… Linux Kernel 5.10.102 / 5.15.25+ Fix from $1,9502022-03-10 CRITICAL 9.8 CVE-2022-26318 KEVEPSS 78% On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS b… Fireware 12.1.3 / 12.5.9+ Fix from $2,3002022-03-04 CRITICAL 10.0 CVE-2022-22947 KEVEPSS 98% In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoi… Spring Cloud Gateway 3.0.7+ Fix from $2,3002022-03-03 HIGH 7.8 CVE-2022-0492 KEVEPSS 6% A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circum… Linux Kernel 4.9.301 / 4.14.266+ Fix from $1,9502022-03-03 HIGH 7.8 CVE-2022-22706 KEV Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, … Bifrost Gpu Kernel Driver Mitigation only Fix from $1,9502022-03-03 HIGH 8.8 CVE-2022-23176 KEVEPSS 13% WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session… Fireware 12.1.3 / 12.5.7+ Fix from $1,9502022-02-24 CRITICAL 10.0 CVE-2022-0543 KEVEPSS 99% It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which c… Redis Patch available Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2021-45382 KEVEPSS 98% A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L rout… Dir 820l Firmware Mitigation only Fix from $2,3002022-02-17 HIGH 7.8 CVE-2021-3560 KEVEPSS 22% It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r… Debian Linux 0.119+ Fix from $1,9502022-02-16 CRITICAL 9.8 CVE-2022-24086 KEVEPSS 99% Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the check… Commerce 2.3.0+ Fix from $2,3002022-02-16 HIGH 8.8 CVE-2021-4102 KEVEPSS 8% Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 96.0.4664.110+ Fix from $1,9502022-02-11 HIGH 8.4 CVE-2022-0185 KEVEPSS 25% A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel ve… Linux Kernel 5.4.173 / 5.10.93+ Fix from $1,9502022-02-11 CRITICAL 9.8 CVE-2022-24112 KEVEPSS 96% An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX … Apisix 2.10.4 / 2.12.1+ Fix from $2,3002022-02-11 HIGH 8.0 CVE-2022-20708 KEVEPSS 15% Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex… Rv340 Firmware after 1.0.03.24 Fix from $1,9502022-02-10 HIGH 8.0 CVE-2022-20703 KEVEPSS 9% Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex… Rv340 Firmware after 1.0.03.24 Fix from $1,9502022-02-10 HIGH 7.8 CVE-2022-20701 KEVEPSS 10% Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex… Rv340 Firmware after 1.0.03.24 Fix from $1,9502022-02-10 CRITICAL 9.8 CVE-2022-20700 KEVEPSS 6% Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex… Rv340 Firmware after 1.0.03.24 Fix from $2,3002022-02-10 CRITICAL 9.8 CVE-2022-20699 KEVEPSS 72% Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex… Rv340 Firmware after 1.0.03.24 Fix from $2,3002022-02-10 CRITICAL 10.0 CVE-2022-22536 KEVEPSS 98% SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulne… Content Server Mitigation only Fix from $2,3002022-02-09 HIGH 7.8 CVE-2022-22718 KEVEPSS 18% Windows Print Spooler Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19204 / 10.0.14393.4946+ Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-21999 KEVEPSS 42% Windows Print Spooler Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19204 / 10.0.14393.4946+ Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-21971 KEVEPSS 54% Windows Runtime Remote Code Execution Vulnerability Windows 10 1809 10.0.17763.2565 / 10.0.18363.2094+ Fix from $1,9502022-02-09 MEDIUM 6.1 CVE-2022-24682 KEVEPSS 31% An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild start… Zimbra Collaboration Suite 8.8.15+ Fix from $1,6002022-02-09 HIGH 7.8 CVE-2021-4034 KEVEPSS 95% A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg… Enterprise Linux Server Update Services For Sap Solutions Patch available Fix from $1,9502022-01-28 HIGH 7.2 CVE-2021-40407 KEVEPSS 48% An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], bas… Rlc 410w Firmware Mitigation only Fix from $1,9502022-01-28 HIGH 7.0 CVE-2021-22600 KEVEPSS 6% A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or … Linux Kernel 4.14.259 / 4.19.222+ Fix from $1,9502022-01-26