Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24124 1 Casbin 1 Casdoor 2022-04-05 5.0 MEDIUM 7.5 HIGH
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
CVE-2022-24789 1 Orckestra 1 C1 Cms 2022-04-05 6.5 MEDIUM 7.6 HIGH
C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The attacker may also truncate arbitrary files to zero size (effectively delete them) leading to denial of service (DoS) or altering application logic. The authenticated user may unknowingly perform the actions by visiting a specially crafted site. Patched in C1 CMS v6.12, no known workarounds exist.
CVE-2021-35490 1 Thruk 1 Thruk 2022-04-05 3.5 LOW 5.4 MEDIUM
Thruk before 2.44 allows XSS for a quick command.
CVE-2022-0726 1 Framasoft 1 Peertube 2022-04-05 5.5 MEDIUM 5.4 MEDIUM
Improper Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
CVE-2022-21926 1 Microsoft 1 Hevc Video Extensions 2022-04-05 6.8 MEDIUM 7.8 HIGH
HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21844, CVE-2022-21927.
CVE-2019-8934 2 Opensuse, Qemu 2 Leap, Qemu 2022-04-05 2.1 LOW 3.3 LOW
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest.
CVE-2019-9896 3 Microsoft, Opensuse, Putty 4 Windows, Backports Sle, Leap and 1 more 2022-04-05 4.6 MEDIUM 7.8 HIGH
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
CVE-2019-9924 5 Canonical, Debian, Gnu and 2 more 6 Ubuntu Linux, Debian Linux, Bash and 3 more 2022-04-05 7.2 HIGH 7.8 HIGH
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
CVE-2022-23937 1 Windriver 1 Vxworks 2022-04-05 5.0 MEDIUM 7.5 HIGH
In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.
CVE-2019-9942 2 Debian, Symfony 2 Debian Linux, Twig 2022-04-05 4.3 MEDIUM 3.7 LOW
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
CVE-2022-24956 1 Shopware 1 B2b Suite 2022-04-05 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
CVE-2016-1455 1 Cisco 8 Nexus 93128, Nexus 9396px, Nexus 9396tx and 5 more 2022-04-05 5.0 MEDIUM 7.5 HIGH
Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CSCuz05365.
CVE-2022-22623 2022-04-05 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2021-46007 1 Totolink 2 Ar3100r, Ar3100r Firmware 2022-04-05 10.0 HIGH 9.8 CRITICAL
totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.
CVE-2021-43663 1 Totolink 2 Ex300 V2, Ex300 V2 Firmware 2022-04-05 7.9 HIGH 7.5 HIGH
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.
CVE-2021-43661 1 Totolink 2 Ex300 V2, Ex300 V2 Firmware 2022-04-05 4.3 MEDIUM 6.1 MEDIUM
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.
CVE-2022-27250 1 Unisoc 1 Unisoc Chipset 2022-04-05 10.0 HIGH 9.8 CRITICAL
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.
CVE-2022-25008 1 Totolink 4 Ex1200t, Ex1200t Firmware, Ex300 V2 and 1 more 2022-04-05 5.8 MEDIUM 8.8 HIGH
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
CVE-2021-46010 1 Totolink 2 A3100r, A3100r Firmware 2022-04-05 6.5 MEDIUM 8.8 HIGH
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
CVE-2021-46009 1 Totolink 2 A3100r, A3100r Firmware 2022-04-05 10.0 HIGH 9.8 CRITICAL
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.