Search
32,636 CVEs · Critical severity
CVEs (32,636, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 32,636 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34882 | CRITICAL | Patched | 9.0 | 2022-09-06 | Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to gain sensitive informat… |
| CVE-2022-36045 | CRITICAL | Patched | 9.0 | 2022-08-31 | NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time not… |
| CVE-2022-28712 | CRITICAL | 9.0 | 2022-08-22 | A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can … | |
| CVE-2022-35975 | CRITICAL | Patched | 9.0 | 2022-08-18 | The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running … |
| CVE-2022-20827 | CRITICAL | Patched | 9.0 | 2022-08-10 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or … |
| CVE-2022-20842 | CRITICAL | Patched | 9.0 | 2022-08-10 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or … |
| CVE-2022-20841 | CRITICAL | Patched | 9.0 | 2022-08-10 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or … |
| CVE-2022-36956 | CRITICAL | 9.0 | 2022-07-27 | In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from… | |
| CVE-2022-35131 | CRITICAL | 9.0 | 2022-07-25 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. | |
| CVE-2022-20812 | CRITICAL | Patched | 9.0 | 2022-07-06 | Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow… |
| CVE-2022-20813 | CRITICAL | Patched | 9.0 | 2022-07-06 | Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow… |
| CVE-2021-43702 | CRITICAL | 9.0 | 2022-07-05 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able t… | |
| CVE-2022-31098 | CRITICAL | Patched | 9.0 | 2022-06-27 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging … |
| CVE-2022-31035 | CRITICAL | Patched | 9.0 | 2022-06-27 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug al… |
| CVE-2022-32158 | CRITICAL | Patched | 9.0 | 2022-06-15 | Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment s… |
| CVE-2021-30339 | CRITICAL | 9.0 | 2022-06-14 | Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdrago… | |
| CVE-2022-21122 | CRITICAL | Patched | 9.0 | 2022-06-08 | The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user… |
| CVE-2022-26857 | CRITICAL | Patched | 9.0 | 2022-05-26 | Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potential… |
| CVE-2022-0947 | CRITICAL | Patched | 9.0 | 2022-05-10 | A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or pr… |
| CVE-2022-24039 | CRITICAL | Patched | 9.0 | 2022-05-10 | A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The “addCell” JavaScript function… |
| CVE-2022-30284 | CRITICAL | Patched | 9.0 | 2022-05-04 | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the ven… |
| CVE-2021-43932 | CRITICAL | 9.0 | 2022-04-28 | Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. | |
| CVE-2022-28101 | CRITICAL | 9.0 | 2022-04-28 | Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection. | |
| CVE-2022-28464 | CRITICAL | Patched | 9.0 | 2022-04-27 | Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution. |
| CVE-2022-1345 | CRITICAL | Patched | 9.0 | 2022-04-13 | Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it ca… |