Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-13516 | 1 Osisoft | 1 Pi Web Api | 2023-03-07 | 6.8 MEDIUM | 8.8 HIGH |
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect. | |||||
CVE-2019-15237 | 2 Fedoraproject, Roundcube | 2 Fedora, Webmail | 2023-03-07 | 4.3 MEDIUM | 7.4 HIGH |
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. | |||||
CVE-2022-35265 | 1 Robustel | 2 R1510, R1510 Firmware | 2023-03-07 | N/A | 7.5 HIGH |
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of service is in the `/action/import_nodejs_app/` API. | |||||
CVE-2022-39348 | 2 Debian, Twistedmatrix | 2 Debian Linux, Twisted | 2023-03-07 | N/A | 5.4 MEDIUM |
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. In practice this should be very difficult to exploit as being able to modify the Host header of a normal HTTP request implies that one is already in a privileged position. This issue was fixed in version 22.10.0rc1. There are no known workarounds. | |||||
CVE-2022-37032 | 2 Debian, Frrouting | 2 Debian Linux, Frrouting | 2023-03-07 | N/A | 9.1 CRITICAL |
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c. | |||||
CVE-2022-26418 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26416 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26347 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26339 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26123 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26087 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26058 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26055 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26053 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26039 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26031 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-26027 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-25997 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-25968 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. | |||||
CVE-2022-25957 | 2023-03-07 | N/A | N/A | ||
This candidate was in a CNA pool that was not assigned to any issues during 2022. |