Search
32,629 CVEs · Critical severity
CVEs (32,629, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 32,629 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1346 | CRITICAL | Patched | 9.0 | 2022-04-13 | Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to ses… |
| CVE-2022-1344 | CRITICAL | Patched | 9.0 | 2022-04-13 | Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's … |
| CVE-2021-42136 | CRITICAL | Patched | 9.0 | 2022-04-13 | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the … |
| CVE-2022-20754 | CRITICAL | Patched | 9.0 | 2022-04-06 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an au… |
| CVE-2022-20755 | CRITICAL | Patched | 9.0 | 2022-04-06 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an au… |
| CVE-2022-23631 | CRITICAL | Patched | 9.0 | 2022-02-09 | superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on an… |
| CVE-2022-24123 | CRITICAL | Patched | 9.0 | 2022-01-29 | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross… |
| CVE-2022-21686 | CRITICAL | Patched | 9.0 | 2022-01-26 | PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back off… |
| CVE-2022-21969 | CRITICAL | 9.0 | 2022-01-11 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2022-21901 | CRITICAL | 9.0 | 2022-01-11 | Windows Hyper-V Elevation of Privilege Vulnerability | |
| CVE-2022-21855 | CRITICAL | 9.0 | 2022-01-11 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2022-21846 | CRITICAL | 9.0 | 2022-01-11 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2022-22115 | CRITICAL | Patched | 9.0 | 2022-01-10 | In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in… |
| CVE-2021-4139 | CRITICAL | Patched | 9.0 | 2021-12-21 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-43882 | CRITICAL | Patched | 9.0 | 2021-12-15 | Microsoft Defender for IoT Remote Code Execution Vulnerability |
| CVE-2021-45046 | CRITICAL | Patched | 9.0 | 2021-12-14 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control ov… |
| CVE-2021-24922 | CRITICAL | Patched | 9.0 | 2021-12-13 | The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attack… |
| CVE-2021-40333 | CRITICAL | Patched | 9.0 | 2021-12-02 | Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing conf… |
| CVE-2021-3985 | CRITICAL | Patched | 9.0 | 2021-12-01 | kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-43787 | CRITICAL | Patched | 9.0 | 2021-11-29 | Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject ar… |
| CVE-2021-3554 | CRITICAL | Patched | 9.0 | 2021-11-24 | Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipul… |
| CVE-2021-23732 | CRITICAL | 9.0 | 2021-11-22 | This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least be partially controlled by a user, they will be in a … | |
| CVE-2021-23155 | CRITICAL | Patched | 9.0 | 2021-11-18 | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects:… |
| CVE-2021-43047 | CRITICAL | Patched | 9.0 | 2021-11-16 | The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) v… |
| CVE-2021-42114 | CRITICAL | 9.0 | 2021-11-16 | Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Ro… |