Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2019-18426 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Meta platforms meta-platforms (CVE-2019-18426)
cross-site scripting in Meta platforms meta-platforms (CVE-2019-18426). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-5002 KEV |
|
[KEV] Out-of-Bounds Write in Adobe flash-player (CVE-2018-5002)
out-of-bounds write in Adobe flash-player (CVE-2018-5002). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-8589 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2018-8589)
vulnerability in Microsoft win32k (CVE-2018-8589). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-1734 |
|
Use-After-Free in c (CVE-2022-1734)
vulnerability in c (CVE-2022-1734). Successful exploitation can lead to full system takeover.
|
| CVE-2022-30065 |
|
Use-After-Free in dos (CVE-2022-30065)
vulnerability in dos (CVE-2022-30065). Successful exploitation can lead to full system takeover.
|
| CVE-2022-29641 |
|
Out-of-Bounds Write in dos (CVE-2022-29641)
out-of-bounds write in dos (CVE-2022-29641). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-5287 |
|
Vulnerability in progress (CVE-2014-5287)
vulnerability in progress (CVE-2014-5287). Successful exploitation can lead to full system takeover.
|
| CVE-2015-1916 |
|
Vulnerability in dos (CVE-2015-1916)
vulnerability in dos (CVE-2015-1916). Risk of unauthorized operations or information disclosure.
|
| CVE-2011-0539 |
|
Vulnerability in c (CVE-2011-0539)
vulnerability in c (CVE-2011-0539). Confidential information can be exposed externally.
|
| CVE-2010-5107 |
|
Vulnerability in dos (CVE-2010-5107)
vulnerability in dos (CVE-2010-5107). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-30525 KEV |
|
[KEV] OS Command Injection in Zyxel multiple-firewalls (CVE-2022-30525)
OS command injection in Zyxel multiple-firewalls (CVE-2022-30525). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-22947 KEV |
|
[KEV] Code Injection in Vmware spring-cloud-gateway (CVE-2022-22947)
code injection in Vmware spring-cloud-gateway (CVE-2022-22947). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-10010 |
|
Vulnerability in c (CVE-2016-10010)
vulnerability in c (CVE-2016-10010). Successful exploitation can lead to full system takeover.
|
| CVE-2018-8727 |
|
Path Traversal in path-traversal (CVE-2018-8727)
path traversal in path-traversal (CVE-2018-8727). Confidential information can be exposed externally.
|
| CVE-2016-8858 |
|
Vulnerability in c (CVE-2016-8858)
vulnerability in c (CVE-2016-8858). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-22983 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2020-22983)
SSRF in ssrf (CVE-2020-22983). Confidential information can be exposed externally.
|
| CVE-2022-25762 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762)
vulnerability in org.apache.tomcat:tomcat (CVE-2022-25762). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.20` or later.
|
| CVE-2018-19908 |
|
OS Command Injection in misp-project (CVE-2018-19908)
OS command injection in misp-project (CVE-2018-19908). Successful exploitation can lead to full system takeover.
|
| CVE-2018-3615 |
|
Vulnerability in intel (CVE-2018-3615)
vulnerability in intel (CVE-2018-3615). Confidential information can be exposed externally.
|
| CVE-2015-5600 |
|
Vulnerability in c (CVE-2015-5600)
vulnerability in c (CVE-2015-5600). Successful exploitation can lead to full system takeover.
|
| CVE-2018-7798 |
|
Vulnerability in schneider-electric (CVE-2018-7798)
vulnerability in schneider-electric (CVE-2018-7798). Data can be tampered with by attackers.
|
| CVE-2018-7792 |
|
Vulnerability in schneider-electric (CVE-2018-7792)
vulnerability in schneider-electric (CVE-2018-7792). Confidential information can be exposed externally.
|
| CVE-2018-7789 |
|
Vulnerability in schneider-electric (CVE-2018-7789)
vulnerability in schneider-electric (CVE-2018-7789). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-23742 |
|
Vulnerability in checkpoint (CVE-2022-23742)
vulnerability in checkpoint (CVE-2022-23742). Successful exploitation can lead to full system takeover.
|
| CVE-2020-19228 |
|
Unrestricted File Upload in bludit (CVE-2020-19228)
vulnerability in bludit (CVE-2020-19228). Successful exploitation can lead to full system takeover.
|
| CVE-2022-29145 |
|
Vulnerability in Microsoft.AspNetCore.App.Runtime.win-x64 (CVE-2022-29145)
vulnerability in Microsoft.AspNetCore.App.Runtime.win-x64 (CVE-2022-29145). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.5` or later.
|
| CVE-2022-29109 |
|
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
|
| CVE-2022-29117 |
|
.NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
|
| CVE-2022-26926 |
|
Windows Address Book Remote Code Execution Vulnerability.
Windows Address Book Remote Code Execution Vulnerability.
|
| CVE-2022-28986 |
|
Vulnerability in lmsdoctor (CVE-2022-28986)
vulnerability in lmsdoctor (CVE-2022-28986). Data can be tampered with by attackers.
|
| CVE-2022-26987 |
|
Out-of-Bounds Write in tp-link (CVE-2022-26987)
out-of-bounds write in tp-link (CVE-2022-26987). Successful exploitation can lead to full system takeover. Exploitable via ``MmtAtePrase``.
|
| CVE-2022-26988 |
|
Out-of-Bounds Write in tp-link (CVE-2022-26988)
out-of-bounds write in tp-link (CVE-2022-26988). Successful exploitation can lead to full system takeover. Exploitable via ``MntAte``.
|
| CVE-2022-1388 KEV |
|
[KEV] Vulnerability in F5 big-ip (CVE-2022-1388)
vulnerability in F5 big-ip (CVE-2022-1388). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-27224 |
|
An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated...
An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated...
|
| CVE-2021-43164 |
|
OS Command Injection in ruijienetworks (CVE-2021-43164)
OS command injection in ruijienetworks (CVE-2021-43164). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43159 |
|
Command Injection in ruijienetworks (CVE-2021-43159)
command injection in ruijienetworks (CVE-2021-43159). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43160 |
|
Command Injection in ruijienetworks (CVE-2021-43160)
command injection in ruijienetworks (CVE-2021-43160). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43161 |
|
Command Injection in ruijienetworks (CVE-2021-43161)
command injection in ruijienetworks (CVE-2021-43161). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43162 |
|
Command Injection in ruijienetworks (CVE-2021-43162)
command injection in ruijienetworks (CVE-2021-43162). Successful exploitation can lead to full system takeover.
|
| CVE-2021-1789 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2021-1789)
vulnerability in Apple multiple-products (CVE-2021-1789). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-8506 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2019-8506)
vulnerability in Apple multiple-products (CVE-2019-8506). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-4113 KEV |
|
[KEV] Vulnerability in Microsoft win32k (CVE-2014-4113)
vulnerability in Microsoft win32k (CVE-2014-4113). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-0322 KEV |
|
[KEV] Use-After-Free in Microsoft internet-explorer (CVE-2014-0322)
vulnerability in Microsoft internet-explorer (CVE-2014-0322). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-0160 KEV |
|
[KEV] Out-of-Bounds Read in openssl (CVE-2014-0160)
vulnerability in openssl (CVE-2014-0160). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-20715 |
|
Vulnerability in dos (CVE-2022-20715)
vulnerability in dos (CVE-2022-20715). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-20745 |
|
Vulnerability in dos (CVE-2022-20745)
vulnerability in dos (CVE-2022-20745). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-20746 |
|
Vulnerability in dos (CVE-2022-20746)
vulnerability in dos (CVE-2022-20746). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-20751 |
|
Vulnerability in dos (CVE-2022-20751)
vulnerability in dos (CVE-2022-20751). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-20757 |
|
Vulnerability in dos (CVE-2022-20757)
vulnerability in dos (CVE-2022-20757). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-20759 |
|
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authen...
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is...
|