Search
32,636 CVEs · Critical severity
CVEs (32,636, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 32,636 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34322 | CRITICAL | 9.0 | 2023-01-01 | Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the context of users' browsers. The attac… | |
| CVE-2022-4866 | CRITICAL | Patched | 9.0 | 2022-12-31 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4865 | CRITICAL | Patched | 9.0 | 2022-12-31 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-31358 | CRITICAL | Patched | 9.0 | 2022-12-14 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non… |
| CVE-2022-41563 | CRITICAL | Patched | 9.0 | 2022-12-13 | The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports… |
| CVE-2022-37721 | CRITICAL | 9.0 | 2022-11-25 | PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post,… | |
| CVE-2022-37720 | CRITICAL | 9.0 | 2022-11-25 | Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascr… | |
| CVE-2022-41943 | CRITICAL | Patched | 9.0 | 2022-11-22 | sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was e… |
| CVE-2022-42989 | CRITICAL | Patched | 9.0 | 2022-11-22 | ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada. |
| CVE-2022-41938 | CRITICAL | Patched | 9.0 | 2022-11-19 | Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change wa… |
| CVE-2022-41558 | CRITICAL | Patched | 9.0 | 2022-11-15 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Mark… |
| CVE-2022-40287 | CRITICAL | 9.0 | 2022-10-31 | The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation … | |
| CVE-2022-40288 | CRITICAL | 9.0 | 2022-10-31 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges withi… | |
| CVE-2022-40289 | CRITICAL | 9.0 | 2022-10-31 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privile… | |
| CVE-2022-32176 | CRITICAL | Patched | 9.0 | 2022-10-17 | In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" fun… |
| CVE-2022-32177 | CRITICAL | Patched | 9.0 | 2022-10-14 | In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' fu… |
| CVE-2022-32174 | CRITICAL | Patched | 9.0 | 2022-10-11 | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. |
| CVE-2021-44171 | CRITICAL | Patched | 9.0 | 2022-10-10 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through… |
| CVE-2022-42308 | CRITICAL | Patched | 9.0 | 2022-10-03 | An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path travers… |
| CVE-2022-42302 | CRITICAL | Patched | 9.0 | 2022-10-03 | An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the N… |
| CVE-2022-39256 | CRITICAL | Patched | 9.0 | 2022-09-27 | Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected inst… |
| CVE-2022-2566 | CRITICAL | 9.0 | 2022-09-23 | A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `s… | |
| CVE-2022-25652 | CRITICAL | 9.0 | 2022-09-16 | Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking | |
| CVE-2020-19586 | CRITICAL | 9.0 | 2022-09-14 | Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI. | |
| CVE-2022-39205 | CRITICAL | Patched | 9.0 | 2022-09-13 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there … |