Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-44596 |
|
Vulnerability in wondershare (CVE-2021-44596)
vulnerability in wondershare (CVE-2021-44596). Successful exploitation can lead to full system takeover.
|
| CVE-2021-41945 |
|
Vulnerability in encode (CVE-2021-41945)
vulnerability in encode (CVE-2021-41945). Confidential information can be exposed externally. Exploitable via ``httpx.URL``.
|
| CVE-2022-27984 |
|
SQL Injection in sqli (CVE-2022-27984)
SQL injection in sqli (CVE-2022-27984). Successful exploitation can lead to full system takeover.
|
| CVE-2022-27985 |
|
SQL Injection in sqli (CVE-2022-27985)
SQL injection in sqli (CVE-2022-27985). Successful exploitation can lead to full system takeover.
|
| CVE-2022-28093 |
|
Vulnerability in online-sports-complex-booking-system-project (CVE-2022-28093)
vulnerability in online-sports-complex-booking-system-project (CVE-2022-28093). Successful exploitation can lead to full system takeover.
|
| CVE-2022-29528 |
|
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
|
| CVE-2018-7602 KEV |
|
[KEV] Code Injection in Drupal core (CVE-2018-7602)
code injection in Drupal core (CVE-2018-7602). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-20753 KEV |
|
[KEV] Vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2018-20753)
vulnerability in Kaseya virtual-systemserver-administrator-vsa (CVE-2018-20753). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-27262 |
|
Unrestricted File Upload in sailsjs (CVE-2022-27262)
vulnerability in sailsjs (CVE-2022-27262). Successful exploitation can lead to full system takeover.
|
| CVE-2022-28397 |
|
Unrestricted File Upload in ghost (CVE-2022-28397)
vulnerability in ghost (CVE-2022-28397). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.42.1` or later.
|
| CVE-2022-27260 |
|
Unrestricted File Upload in buttercms (CVE-2022-27260)
vulnerability in buttercms (CVE-2022-27260). Successful exploitation can lead to full system takeover.
|
| CVE-2021-37291 |
|
SQL Injection in sqli (CVE-2021-37291)
SQL injection in sqli (CVE-2021-37291). Successful exploitation can lead to full system takeover.
|
| CVE-2022-26645 |
|
Unrestricted File Upload in oretnom23 (CVE-2022-26645)
vulnerability in oretnom23 (CVE-2022-26645). Successful exploitation can lead to full system takeover.
|
| CVE-2022-26646 |
|
Vulnerability in oretnom23 (CVE-2022-26646)
vulnerability in oretnom23 (CVE-2022-26646). Successful exploitation can lead to full system takeover.
|
| CVE-2021-46007 |
|
OS Command Injection in totolink (CVE-2021-46007)
OS command injection in totolink (CVE-2021-46007). Successful exploitation can lead to full system takeover.
|
| CVE-2021-46009 |
|
Vulnerability in totolink (CVE-2021-46009)
vulnerability in totolink (CVE-2021-46009). Successful exploitation can lead to full system takeover.
|
| CVE-2022-25521 |
|
UNNO v03.11.00 was discovered to contain access control issue.
UNNO v03.11.00 was discovered to contain access control issue.
|
| CVE-2010-2861 KEV |
|
[KEV] Path Traversal in Adobe coldfusion (CVE-2010-2861)
path traversal in Adobe coldfusion (CVE-2010-2861). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-1273 KEV |
|
[KEV] Code Injection in Vmware tanzu vmware-tanzu (CVE-2018-1273)
code injection in Vmware tanzu vmware-tanzu (CVE-2018-1273). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-11138 KEV |
|
[KEV] OS Command Injection in Quest kace-system-management-appliance (CVE-2018-11138)
OS command injection in Quest kace-system-management-appliance (CVE-2018-11138). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-15107 KEV |
|
[KEV] OS Command Injection in webmin (CVE-2019-15107)
OS command injection in webmin (CVE-2019-15107). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42237 KEV |
|
[KEV] Unsafe Deserialization in Sitecore xp (CVE-2021-42237)
vulnerability in Sitecore xp (CVE-2021-42237). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-24292 |
|
Vulnerability in dos (CVE-2022-24292)
vulnerability in dos (CVE-2022-24292). Successful exploitation can lead to full system takeover.
|
| CVE-2022-24293 |
|
Vulnerability in dos (CVE-2022-24293)
vulnerability in dos (CVE-2022-24293). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45756 |
|
Vulnerability in asus (CVE-2021-45756)
vulnerability in asus (CVE-2021-45756). Successful exploitation can lead to full system takeover.
|
| CVE-2022-25578 |
|
Code Injection in taogogo (CVE-2022-25578)
code injection in taogogo (CVE-2022-25578). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45834 |
|
Unrestricted File Upload in opendocman (CVE-2021-45834)
vulnerability in opendocman (CVE-2021-45834). Successful exploitation can lead to full system takeover.
|
| CVE-2021-44087 |
|
Vulnerability in attendance-and-payroll-system-project (CVE-2021-44087)
vulnerability in attendance-and-payroll-system-project (CVE-2021-44087). Successful exploitation can lead to full system takeover.
|
| CVE-2021-44088 |
|
SQL Injection in sqli (CVE-2021-44088)
SQL injection in sqli (CVE-2021-44088). Successful exploitation can lead to full system takeover.
|
| CVE-2021-44620 |
|
Command Injection in totolink (CVE-2021-44620)
command injection in totolink (CVE-2021-44620). Successful exploitation can lead to full system takeover.
|
| CVE-2022-23383 |
|
Authentication Bypass in yzmcms (CVE-2022-23383)
authentication bypass in yzmcms (CVE-2022-23383). Confidential information can be exposed externally.
|
| CVE-2022-0715 |
|
Authentication Bypass in schneider-electric (CVE-2022-0715)
authentication bypass in schneider-electric (CVE-2022-0715). Data can be tampered with by attackers.
|
| CVE-2022-26486 KEV |
|
[KEV] Use-After-Free in Mozilla firefox (CVE-2022-26486)
vulnerability in Mozilla firefox (CVE-2022-26486). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-22051 |
|
Vulnerability in commonmarker (CVE-2024-22051)
vulnerability in commonmarker (CVE-2024-22051). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.23.4` or later.
|
| CVE-2022-25089 |
|
Printix Secure Cloud Print Management 1.3.1035.0 incorrectly uses Privileged APIs.
Printix Secure Cloud Print Management 1.3.1035.0 incorrectly uses Privileged APIs.
|
| CVE-2012-0507 KEV |
|
[KEV] Vulnerability in Oracle java-se (CVE-2012-0507)
vulnerability in Oracle java-se (CVE-2012-0507). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2012-1723 KEV |
|
[KEV] Vulnerability in Oracle java-se (CVE-2012-1723)
vulnerability in Oracle java-se (CVE-2012-1723). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2012-4681 KEV |
|
[KEV] Vulnerability in Oracle java-se (CVE-2012-4681)
vulnerability in Oracle java-se (CVE-2012-4681). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-1019 KEV |
|
[KEV] Vulnerability in Adobe flash-player (CVE-2016-1019)
vulnerability in Adobe flash-player (CVE-2016-1019). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-1938 KEV |
|
[KEV] Privilege Escalation in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938)
vulnerability in org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `7.0.100` or later.
|
| CVE-2022-25060 |
|
OS Command Injection in tp-link (CVE-2022-25060)
OS command injection in tp-link (CVE-2022-25060). Successful exploitation can lead to full system takeover.
|
| CVE-2022-25064 |
|
OS Command Injection in tp-link (CVE-2022-25064)
OS command injection in tp-link (CVE-2022-25064). Successful exploitation can lead to full system takeover.
|
| CVE-2022-25061 |
|
OS Command Injection in tp-link (CVE-2022-25061)
OS command injection in tp-link (CVE-2022-25061). Successful exploitation can lead to full system takeover.
|
| CVE-2021-42952 |
|
Vulnerability in zepl (CVE-2021-42952)
vulnerability in zepl (CVE-2021-42952). Successful exploitation can lead to full system takeover.
|
| CVE-2022-0664 |
|
Vulnerability in netmaker (CVE-2022-0664)
vulnerability in netmaker (CVE-2022-0664). Successful exploitation can lead to full system takeover.
|
| CVE-2022-22916 |
|
Vulnerability in zoneland (CVE-2022-22916)
vulnerability in zoneland (CVE-2022-22916). Successful exploitation can lead to full system takeover.
|
| CVE-2022-23304 |
|
Vulnerability in w1fi (CVE-2022-23304)
vulnerability in w1fi (CVE-2022-23304). Successful exploitation can lead to full system takeover.
|
| CVE-2022-23303 |
|
Vulnerability in w1fi (CVE-2022-23303)
vulnerability in w1fi (CVE-2022-23303). Successful exploitation can lead to full system takeover.
|
| CVE-2021-45420 |
|
Information Disclosure in dos (CVE-2021-45420)
vulnerability in dos (CVE-2021-45420). Successful exploitation can lead to full system takeover.
|
| CVE-2020-0796 KEV |
|
[KEV] Buffer Overflow in Microsoft smbv3 (CVE-2020-0796)
vulnerability in Microsoft smbv3 (CVE-2020-0796). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|