Search Results (30281 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-0318 4 Apple, Debian, Redhat and 1 more 4 Macos, Debian Linux, Enterprise Linux and 1 more 2024-11-21 9.8 Critical
Heap-based Buffer Overflow in vim/vim prior to 8.2.
CVE-2022-0290 1 Google 1 Chrome 2024-11-21 9.6 Critical
Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2022-0272 1 Detekt 1 Detekt 2024-11-21 9.8 Critical
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
CVE-2022-0265 1 Hazelcast 1 Hazelcast 2024-11-21 9.8 Critical
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
CVE-2022-0254 1 Highfivery 1 Zero-spam 2024-11-21 9.8 Critical
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection
CVE-2022-0224 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 9.8 Critical
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
CVE-2022-0169 1 10web 1 Photo Gallery 2024-11-21 9.8 Critical
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
CVE-2022-0142 1 Vfbpro 1 Visual Form Builder 2024-11-21 9.8 Critical
The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
CVE-2022-0139 1 Radare 1 Radare2 2024-11-21 9.8 Critical
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
CVE-2022-0097 2 Fedoraproject, Google 2 Fedora, Chrome 2024-11-21 9.6 Critical
Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.
CVE-2022-0086 1 Transloadit 1 Uppy 2024-11-21 9.8 Critical
uppy is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2021-4171 1 Janeczku 1 Calibre-web 2024-11-21 9.8 Critical
calibre-web is vulnerable to Business Logic Errors
CVE-2021-4161 1 Moxa 6 Mgate Mb3180, Mgate Mb3180 Firmware, Mgate Mb3280 and 3 more 2024-11-21 9.8 Critical
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
CVE-2021-4139 1 Pimcore 1 Pimcore 2024-11-21 9.0 Critical
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4119 1 Bookstackapp 1 Bookstack 2024-11-21 9.8 Critical
bookstack is vulnerable to Improper Access Control
CVE-2021-4070 1 V2fly 1 V2ray-core 2024-11-21 9.1 Critical
Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.
CVE-2021-4048 5 Fedoraproject, Julialang, Lapack Project and 2 more 8 Fedora, Julia, Lapack and 5 more 2024-11-21 9.1 Critical
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
CVE-2021-4045 1 Tp-link 2 Tapo C200, Tapo C200 Firmware 2024-11-21 9.8 Critical
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.
CVE-2021-4039 1 Zyxel 2 Nwa1100-nh, Nwa1100-nh Firmware 2024-11-21 9.8 Critical
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
CVE-2021-46895 1 Huawei 2 Emui, Harmonyos 2024-11-21 9.1 Critical
Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.