Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2022-42827 KEV |
|
[KEV] Vulnerability in Apple ios-and-ipados (CVE-2022-42827)
vulnerability in Apple ios-and-ipados (CVE-2022-42827). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-19322 KEV |
|
[KEV] Vulnerability in Gigabyte multiple-products (CVE-2018-19322)
vulnerability in Gigabyte multiple-products (CVE-2018-19322). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-19321 KEV |
|
[KEV] Vulnerability in Gigabyte multiple-products (CVE-2018-19321)
vulnerability in Gigabyte multiple-products (CVE-2018-19321). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-19320 KEV |
|
[KEV] Vulnerability in Gigabyte multiple-products (CVE-2018-19320)
vulnerability in Gigabyte multiple-products (CVE-2018-19320). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3433 KEV |
|
[KEV] Vulnerability in Cisco anyconnect-secure (CVE-2020-3433)
vulnerability in Cisco anyconnect-secure (CVE-2020-3433). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-31366 |
|
Unrestricted File Upload in eve-ng (CVE-2022-31366)
vulnerability in eve-ng (CVE-2022-31366). Successful exploitation can lead to full system takeover.
|
| CVE-2022-41352 KEV |
|
[KEV] Path Traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-41352)
path traversal in Synacor zimbra-collaboration-suite-zcs (CVE-2022-41352). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-3493 KEV |
|
[KEV] Vulnerability in Linux kernel (CVE-2021-3493)
vulnerability in Linux kernel (CVE-2021-3493). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-33077 |
|
Vulnerability in nopcommerce (CVE-2022-33077)
vulnerability in nopcommerce (CVE-2022-33077). Data can be tampered with by attackers.
|
| CVE-2021-3305 |
|
Vulnerability in feishu (CVE-2021-3305)
vulnerability in feishu (CVE-2021-3305). Successful exploitation can lead to full system takeover.
|
| CVE-2022-40227 |
|
Vulnerability in dos (CVE-2022-40227)
vulnerability in dos (CVE-2022-40227). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-41033 KEV |
|
[KEV] Vulnerability in Microsoft windows-com-event-system-service (CVE-2022-41033)
vulnerability in Microsoft windows-com-event-system-service (CVE-2022-41033). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-20920 |
|
Vulnerability in cisco (CVE-2022-20920)
vulnerability in cisco (CVE-2022-20920). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-36635 |
|
SQL Injection in sqli (CVE-2022-36635)
SQL injection in sqli (CVE-2022-36635). Successful exploitation can lead to full system takeover.
|
| CVE-2022-36634 |
|
Authorization Flaw in zkteco (CVE-2022-36634)
vulnerability in zkteco (CVE-2022-36634). Successful exploitation can lead to full system takeover.
|
| CVE-2022-40341 |
|
Unrestricted File Upload in mojoportal (CVE-2022-40341)
vulnerability in mojoportal (CVE-2022-40341). Successful exploitation can lead to full system takeover.
|
| CVE-2022-41082 KEV |
|
[KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2022-41082)
vulnerability in Microsoft exchange-server (CVE-2022-41082). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-41040 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2022-41040)
SSRF in Microsoft exchange-server (CVE-2022-41040). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-36804 KEV |
|
[KEV] OS Command Injection in Atlassian bitbucket-server-and-data-center (CVE-2022-36804)
OS command injection in Atlassian bitbucket-server-and-data-center (CVE-2022-36804). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-40048 |
|
Unrestricted File Upload in flatpress (CVE-2022-40048)
vulnerability in flatpress (CVE-2022-40048). Successful exploitation can lead to full system takeover.
|
| CVE-2022-2347 |
|
Vulnerability in denx (CVE-2022-2347)
vulnerability in denx (CVE-2022-2347). Successful exploitation can lead to full system takeover. Exploitable via ``wLength``.
|
| CVE-2022-30426 |
|
Out-of-Bounds Write in acer (CVE-2022-30426)
out-of-bounds write in acer (CVE-2022-30426). Successful exploitation can lead to full system takeover.
|
| CVE-2022-3236 KEV |
|
[KEV] Code Injection in Sophos firewall (CVE-2022-3236)
code injection in Sophos firewall (CVE-2022-3236). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-34026 |
|
ICEcoder v8.1 allows attackers to execute a directory traversal.
ICEcoder v8.1 allows attackers to execute a directory traversal.
|
| CVE-2022-28981 |
|
Path Traversal in path-traversal (CVE-2022-28981)
path traversal in path-traversal (CVE-2022-28981). Confidential information can be exposed externally. Exploitable via ``parameter``.
|
| CVE-2022-35405 KEV |
|
[KEV] Unsafe Deserialization in Zoho manageengine (CVE-2022-35405)
vulnerability in Zoho manageengine (CVE-2022-35405). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-2265 |
|
Path Traversal in path-traversal (CVE-2022-2265)
path traversal in path-traversal (CVE-2022-2265). Confidential information can be exposed externally.
|
| CVE-2022-37700 |
|
Path Traversal in path-traversal (CVE-2022-37700)
path traversal in path-traversal (CVE-2022-37700). Confidential information can be exposed externally.
|
| CVE-2022-38577 |
|
Vulnerability in processmaker (CVE-2022-38577)
vulnerability in processmaker (CVE-2022-38577). Successful exploitation can lead to full system takeover.
|
| CVE-2022-38618 |
|
SQL Injection in sqli (CVE-2022-38618)
SQL injection in sqli (CVE-2022-38618). Successful exploitation can lead to full system takeover.
|
| CVE-2022-38617 |
|
SQL Injection in sqli (CVE-2022-38617)
SQL injection in sqli (CVE-2022-38617). Successful exploitation can lead to full system takeover.
|
| CVE-2022-36534 |
|
Command Injection in syncovery (CVE-2022-36534)
command injection in syncovery (CVE-2022-36534). Successful exploitation can lead to full system takeover.
|
| CVE-2022-36532 |
|
Vulnerability in bolt (CVE-2022-36532)
vulnerability in bolt (CVE-2022-36532). Successful exploitation can lead to full system takeover.
|
| CVE-2022-40139 KEV |
|
[KEV] Vulnerability in Trend micro trend-micro (CVE-2022-40139)
vulnerability in Trend micro trend-micro (CVE-2022-40139). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2013-6282 KEV |
|
[KEV] Vulnerability in Linux kernel (CVE-2013-6282)
vulnerability in Linux kernel (CVE-2013-6282). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2013-2597 KEV |
|
[KEV] Buffer Overflow in Code aurora code-aurora (CVE-2013-2597)
vulnerability in Code aurora code-aurora (CVE-2013-2597). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2013-2596 KEV |
|
[KEV] Vulnerability in Linux kernel (CVE-2013-2596)
vulnerability in Linux kernel (CVE-2013-2596). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2013-2094 KEV |
|
[KEV] Vulnerability in Linux kernel (CVE-2013-2094)
vulnerability in Linux kernel (CVE-2013-2094). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2010-2568 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2010-2568)
vulnerability in Microsoft windows (CVE-2010-2568). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-37969 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2022-37969)
vulnerability in Microsoft windows (CVE-2022-37969). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-32917 KEV |
|
[KEV] Vulnerability in Apple ios (CVE-2022-32917)
vulnerability in Apple ios (CVE-2022-32917). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-38013 |
|
Vulnerability in Microsoft.AspNetCore.App.Runtime.linux-arm (CVE-2022-38013)
vulnerability in Microsoft.AspNetCore.App.Runtime.linux-arm (CVE-2022-38013). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.9` or later.
|
| CVE-2022-38616 |
|
SQL Injection in sqli (CVE-2022-38616)
SQL injection in sqli (CVE-2022-38616). Successful exploitation can lead to full system takeover.
|
| CVE-2022-34109 |
|
Vulnerability in msi (CVE-2022-34109)
vulnerability in msi (CVE-2022-34109). Data can be tampered with by attackers.
|
| CVE-2022-34108 |
|
Vulnerability in dos (CVE-2022-34108)
vulnerability in dos (CVE-2022-34108). Data can be tampered with by attackers.
|
| CVE-2022-36110 |
|
Vulnerability in netmaker (CVE-2022-36110)
vulnerability in netmaker (CVE-2022-36110). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.15.1` or later.
|
| CVE-2022-38614 |
|
Path Traversal in bpcbt (CVE-2022-38614)
path traversal in bpcbt (CVE-2022-38614). Confidential information can be exposed externally.
|
| CVE-2022-38615 |
|
SQL Injection in sqli (CVE-2022-38615)
SQL injection in sqli (CVE-2022-38615). Successful exploitation can lead to full system takeover.
|
| CVE-2022-30079 |
|
OS Command Injection in netgear (CVE-2022-30079)
OS command injection in netgear (CVE-2022-30079). Successful exploitation can lead to full system takeover.
|
| CVE-2022-37144 |
|
Vulnerability in plextrac (CVE-2022-37144)
vulnerability in plextrac (CVE-2022-37144). Successful exploitation can lead to full system takeover.
|