Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26279 1 Eyoucms 1 Eyoucms 2022-03-30 7.5 HIGH 9.8 CRITICAL
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
CVE-2020-20093 1 Facebook 1 Messenger 2022-03-30 4.3 MEDIUM 6.5 MEDIUM
The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
CVE-2020-20094 1 Facebook 1 Instagram 2022-03-30 4.3 MEDIUM 6.5 MEDIUM
Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages
CVE-2021-27476 1 Rockwellautomation 1 Factorytalk Assetcentre 2022-03-30 7.5 HIGH 9.8 CRITICAL
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
CVE-2021-4011 3 Debian, Fedoraproject, X.org 3 Debian Linux, Fedora, X Server 2022-03-30 7.2 HIGH 7.8 HIGH
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-4010 3 Debian, Fedoraproject, X.org 3 Debian Linux, Fedora, X Server 2022-03-30 7.2 HIGH 7.8 HIGH
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-4009 3 Debian, Fedoraproject, X.org 3 Debian Linux, Fedora, X Server 2022-03-30 7.2 HIGH 7.8 HIGH
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-4008 3 Debian, Fedoraproject, X.org 3 Debian Linux, Fedora, X Server 2022-03-30 7.2 HIGH 7.8 HIGH
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-4219 1 Imagemagick 1 Imagemagick 2022-03-30 4.3 MEDIUM 5.5 MEDIUM
A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.
CVE-2021-26599 1 Impresscms 1 Impresscms 2022-03-30 7.5 HIGH 9.8 CRITICAL
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
CVE-2021-26601 1 Impresscms 1 Impresscms 2022-03-30 5.5 MEDIUM 8.1 HIGH
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
CVE-2021-26600 1 Impresscms 1 Impresscms 2022-03-30 7.5 HIGH 9.8 CRITICAL
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
CVE-2021-26089 1 Fortinet 1 Forticlient 2022-03-30 7.2 HIGH 7.8 HIGH
An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands during installation phase.
CVE-2021-44209 1 Open-xchange 1 Ox App Suite 2022-03-30 4.3 MEDIUM 6.1 MEDIUM
OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
CVE-2021-44208 1 Open-xchange 1 Ox App Suite 2022-03-30 4.3 MEDIUM 6.1 MEDIUM
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
CVE-2021-44211 1 Open-xchange 1 Ox App Suite 2022-03-30 3.5 LOW 5.4 MEDIUM
OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
CVE-2021-44210 1 Open-xchange 1 Ox App Suite 2022-03-30 4.3 MEDIUM 6.1 MEDIUM
OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
CVE-2022-26268 1 Xiaohuanxiong Project 1 Xiaohuanxiong 2022-03-30 7.5 HIGH 9.8 CRITICAL
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.
CVE-2021-44617 1 Glpi-project 1 Glpi 2022-03-30 7.5 HIGH 9.8 CRITICAL
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
CVE-2020-20096 1 Whatsapp 1 Whatsapp 2022-03-30 4.3 MEDIUM 6.5 MEDIUM
Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.