Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2022-35278 |
|
Cross-Site Scripting (XSS) in org.apache.activemq:artemis-server (CVE-2022-35278)
cross-site scripting in org.apache.activemq:artemis-server (CVE-2022-35278). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.24.0` or later.
|
| CVE-2022-0028 KEV |
|
[KEV] Vulnerability in Palo alto networks palo-alto-networks (CVE-2022-0028)
vulnerability in Palo alto networks palo-alto-networks (CVE-2022-0028). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-36233 |
|
Out-of-Bounds Write in tendacn (CVE-2022-36233)
out-of-bounds write in tendacn (CVE-2022-36233). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-32894 KEV |
|
[KEV] Vulnerability in Apple ios-and-macos (CVE-2022-32894)
vulnerability in Apple ios-and-macos (CVE-2022-32894). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-32893 KEV |
|
[KEV] Vulnerability in Apple ios-and-macos (CVE-2022-32893)
vulnerability in Apple ios-and-macos (CVE-2022-32893). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-2856 KEV |
|
[KEV] Vulnerability in Google chromium-intents (CVE-2022-2856)
vulnerability in Google chromium-intents (CVE-2022-2856). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-26923 KEV |
|
[KEV] Vulnerability in Microsoft active-directory (CVE-2022-26923)
vulnerability in Microsoft active-directory (CVE-2022-26923). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-21971 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2022-21971)
vulnerability in Microsoft windows (CVE-2022-21971). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-15944 KEV |
|
[KEV] Vulnerability in Palo alto networks palo-alto-networks (CVE-2017-15944)
vulnerability in Palo alto networks palo-alto-networks (CVE-2017-15944). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-22536 KEV |
|
[KEV] Vulnerability in Sap multiple-products (CVE-2022-22536)
vulnerability in Sap multiple-products (CVE-2022-22536). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-36530 |
|
Cross-Site Scripting (XSS) in rageframe (CVE-2022-36530)
cross-site scripting in rageframe (CVE-2022-36530). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-36262 |
|
Code Injection in taogogo (CVE-2022-36262)
code injection in taogogo (CVE-2022-36262). Successful exploitation can lead to full system takeover.
|
| CVE-2022-27925 KEV |
|
[KEV] Path Traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-27925)
path traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-27925). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-37042 KEV |
|
[KEV] Path Traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-37042)
path traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-37042). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-36124 |
|
Vulnerability in apache-avro (CVE-2022-36124)
vulnerability in apache-avro (CVE-2022-36124). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.14.0` or later.
|
| CVE-2022-34713 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2022-34713)
vulnerability in Microsoft windows (CVE-2022-34713). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-30333 KEV |
|
[KEV] Path Traversal in Rarlab unrar (CVE-2022-30333)
path traversal in Rarlab unrar (CVE-2022-30333). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2022-37434 |
|
Out-of-Bounds Write in c (CVE-2022-37434)
out-of-bounds write in c (CVE-2022-37434). Successful exploitation can lead to full system takeover.
|
| CVE-2022-28880 |
|
Vulnerability in f-secure (CVE-2022-28880)
vulnerability in f-secure (CVE-2022-28880). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-27924 KEV |
|
[KEV] Vulnerability in Synacor zimbra-collaboration-suite-zcs (CVE-2022-27924)
vulnerability in Synacor zimbra-collaboration-suite-zcs (CVE-2022-27924). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2022-26138 KEV |
|
[KEV] Vulnerability in Atlassian confluence (CVE-2022-26138)
vulnerability in Atlassian confluence (CVE-2022-26138). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-2160 |
|
Vulnerability in google (CVE-2022-2160)
vulnerability in google (CVE-2022-2160). Confidential information can be exposed externally.
|
| CVE-2022-34611 |
|
Cross-Site Scripting (XSS) in online-fire-reporting-system-project (CVE-2022-34611)
cross-site scripting in online-fire-reporting-system-project (CVE-2022-34611). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-24992 |
|
Path Traversal in path-traversal (CVE-2022-24992)
path traversal in path-traversal (CVE-2022-24992). Confidential information can be exposed externally.
|
| CVE-2022-34169 |
|
Vulnerability in apache (CVE-2022-34169)
vulnerability in apache (CVE-2022-34169). Data can be tampered with by attackers.
|
| CVE-2021-42923 |
|
Vulnerability in showmypc (CVE-2021-42923)
vulnerability in showmypc (CVE-2021-42923). Successful exploitation can lead to full system takeover.
|
| CVE-2022-32119 |
|
Unrestricted File Upload in arox (CVE-2022-32119)
vulnerability in arox (CVE-2022-32119). Successful exploitation can lead to full system takeover.
|
| CVE-2022-30024 |
|
Vulnerability in tp-link (CVE-2022-30024)
vulnerability in tp-link (CVE-2022-30024). Successful exploitation can lead to full system takeover.
|
| CVE-2022-32074 |
|
Cross-Site Scripting (XSS) in enhancesoft (CVE-2022-32074)
cross-site scripting in enhancesoft (CVE-2022-32074). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-31904 |
|
Cross-Site Scripting (XSS) in uberrider (CVE-2022-31904)
cross-site scripting in uberrider (CVE-2022-31904). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-22047 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2022-22047)
vulnerability in Microsoft windows (CVE-2022-22047). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-26925 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2022-26925)
vulnerability in Microsoft windows (CVE-2022-26925). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3837 KEV |
|
[KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2020-3837)
out-of-bounds write in Apple multiple-products (CVE-2020-3837). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-9907 KEV |
|
[KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2020-9907)
out-of-bounds write in Apple multiple-products (CVE-2020-9907). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-8605 KEV |
|
[KEV] Use-After-Free in Apple multiple-products (CVE-2019-8605)
vulnerability in Apple multiple-products (CVE-2019-8605). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-4344 KEV |
|
[KEV] Buffer Overflow in Apple multiple-products (CVE-2018-4344)
vulnerability in Apple multiple-products (CVE-2018-4344). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30983 KEV |
|
[KEV] Buffer Overflow in Apple ios-and-ipados (CVE-2021-30983)
vulnerability in Apple ios-and-ipados (CVE-2021-30983). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-4034 KEV |
|
[KEV] Out-of-Bounds Write in Red hat red-hat (CVE-2021-4034)
out-of-bounds write in Red hat red-hat (CVE-2021-4034). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-29499 KEV |
|
[KEV] Vulnerability in Mitel mivoice-connect (CVE-2022-29499)
vulnerability in Mitel mivoice-connect (CVE-2022-29499). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-30533 KEV |
|
[KEV] Authorization Flaw in Google chromium-popupblocker (CVE-2021-30533)
vulnerability in Google chromium-popupblocker (CVE-2021-30533). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-31384 |
|
SQL Injection in sqli (CVE-2022-31384)
SQL injection in sqli (CVE-2022-31384). Successful exploitation can lead to full system takeover.
|
| CVE-2022-31382 |
|
SQL Injection in sqli (CVE-2022-31382)
SQL injection in sqli (CVE-2022-31382). Successful exploitation can lead to full system takeover.
|
| CVE-2022-31383 |
|
SQL Injection in sqli (CVE-2022-31383)
SQL injection in sqli (CVE-2022-31383). Successful exploitation can lead to full system takeover.
|
| CVE-2021-41672 |
|
SQL Injection in sqli (CVE-2021-41672)
SQL injection in sqli (CVE-2021-41672). Confidential information can be exposed externally.
|
| CVE-2021-42675 |
|
Unrestricted File Upload in kreado (CVE-2021-42675)
vulnerability in kreado (CVE-2021-42675). Successful exploitation can lead to full system takeover.
|
| CVE-2022-30190 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2022-30190)
vulnerability in Microsoft windows (CVE-2022-30190). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41663 |
|
Cross-Site Scripting (XSS) in 1234n (CVE-2021-41663)
cross-site scripting in 1234n (CVE-2021-41663). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-38163 KEV |
|
[KEV] Vulnerability in Sap netweaver (CVE-2021-38163)
vulnerability in Sap netweaver (CVE-2021-38163). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-2386 KEV |
|
[KEV] SQL Injection in Sap netweaver (CVE-2016-2386)
SQL injection in Sap netweaver (CVE-2016-2386). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-2388 KEV |
|
[KEV] Information Disclosure in Sap netweaver (CVE-2016-2388)
vulnerability in Sap netweaver (CVE-2016-2388). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|