Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25237 1 Bonitasoft 1 Bonita Web 2022-06-09 7.5 HIGH 9.8 CRITICAL
Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.
CVE-2021-44080 1 Sercomm 2 H500s, H500s Firmware 2022-06-09 9.0 HIGH 7.2 HIGH
A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.
CVE-2022-26971 1 Barco 1 Control Room Management Suite 2022-06-09 5.0 MEDIUM 5.3 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.
CVE-2022-26972 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
CVE-2022-26973 1 Barco 1 Control Room Management Suite 2022-06-09 5.0 MEDIUM 5.3 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
CVE-2022-26975 1 Barco 1 Control Room Management Suite 2022-06-09 5.0 MEDIUM 7.5 HIGH
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
CVE-2022-26974 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.
CVE-2022-26977 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS.
CVE-2022-26976 1 Barco 1 Control Room Management Suite 2022-06-09 3.5 LOW 5.4 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
CVE-2022-26978 1 Barco 1 Control Room Management Suite 2022-06-09 4.3 MEDIUM 6.1 MEDIUM
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.
CVE-2022-24967 1 Blackrainbow 1 Nimbus 2022-06-09 3.5 LOW 5.4 MEDIUM
Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).
CVE-2021-43308 1 Markdown-link-extractor Project 1 Markdown-link-extractor 2022-06-09 5.0 MEDIUM 7.5 HIGH
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function
CVE-2021-43307 1 Semver-regex Project 1 Semver-regex 2022-06-09 5.0 MEDIUM 7.5 HIGH
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
CVE-2021-34083 1 Google-it Project 1 Google-it 2022-06-09 9.3 HIGH 8.1 HIGH
Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell command, potentially exposing the server to RCE.
CVE-2021-34079 1 Docker-tester Project 1 Docker-tester 2022-06-09 10.0 HIGH 9.8 CRITICAL
OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.
CVE-2021-34080 1 Ssl-utils Project 1 Ssl-utils 2022-06-09 10.0 HIGH 9.8 CRITICAL
OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.
CVE-2021-34081 1 Gitsome Project 1 Gitsome 2022-06-09 9.3 HIGH 8.8 HIGH
OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.
CVE-2021-34082 1 Proctree Project 1 Proctree 2022-06-09 10.0 HIGH 9.8 CRITICAL
OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.
CVE-2021-43306 1 Jqueryvalidation 1 Jquery Validation 2022-06-09 5.0 MEDIUM 7.5 HIGH
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method
CVE-2021-34078 1 Adp 1 Lifion-verifiy-dependencies 2022-06-09 9.3 HIGH 8.8 HIGH
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.