Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29728 1 Surveysparrow 1 Enterprise Survey Software 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.
CVE-2022-0025 2 Microsoft, Paloaltonetworks 2 Windows, Cortex Xdr Agent 2022-05-23 7.2 HIGH 6.7 MEDIUM
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts: All versions of the Cortex XDR agent when upgrading to Cortex XDR agent 7.7.0 on Windows; Cortex XDR agent 7.7.0 without content update 500 or a later version on Windows. This issue does not impact other platforms or other versions of the Cortex XDR agent.
CVE-2021-27054 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2022-05-23 6.8 MEDIUM 7.8 HIGH
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-27053.
CVE-2021-27500 1 Opener Project 1 Opener 2022-05-23 5.0 MEDIUM 7.5 HIGH
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
CVE-2022-29369 1 F5 1 Njs 2022-05-23 5.0 MEDIUM 7.5 HIGH
Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c.
CVE-2020-22985 1 Microstrategy 1 Microstrategy Web Sdk 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.
CVE-2020-22984 1 Microstrategy 1 Microstrategy Web Sdk 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.
CVE-2021-27482 1 Opener Project 1 Opener 2022-05-23 5.0 MEDIUM 7.5 HIGH
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data.
CVE-2021-27478 1 Opener Project 1 Opener 2022-05-23 5.0 MEDIUM 7.5 HIGH
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition.
CVE-2020-22987 1 Microstrategy 1 Microstrategy Web Sdk 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.
CVE-2020-22986 1 Microstrategy 1 Microstrategy Web Sdk 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.
CVE-2021-27498 1 Opener Project 1 Opener 2022-05-23 5.0 MEDIUM 7.5 HIGH
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
CVE-2022-28873 1 F-secure 1 Safe 2022-05-23 4.3 MEDIUM 4.3 MEDIUM
A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.open functionality in SAFE Browser which could lead address bar spoofing attacks.
CVE-2019-7317 11 Canonical, Debian, Hp and 8 more 33 Ubuntu Linux, Debian Linux, Xp7 Command View and 30 more 2022-05-23 2.6 LOW 5.3 MEDIUM
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVE-2021-42863 1 Jerryscript 1 Jerryscript 2022-05-23 7.5 HIGH 9.8 CRITICAL
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.
CVE-2022-28872 1 F-secure 1 Safe 2022-05-23 6.8 MEDIUM 8.8 HIGH
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails in a loop.
CVE-2022-29929 1 Jetbrains 1 Teamcity 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
CVE-2022-29928 1 Jetbrains 1 Teamcity 2022-05-23 4.0 MEDIUM 4.9 MEDIUM
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
CVE-2022-29927 1 Jetbrains 1 Teamcity 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
CVE-2022-29538 1 Resi 1 Gemini-net 2022-05-20 5.0 MEDIUM 5.3 MEDIUM
RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able to access some critical resources.