| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42714 | Hig | 0.51 | 7.8 | 0.00 | Feb 15, 2022 | Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | ||
| CVE-2021-42713 | Hig | 0.51 | 7.8 | 0.00 | Feb 15, 2022 | Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions. | ||
| CVE-2021-43050 | Hig | 0.55 | 8.4 | 0.00 | Feb 15, 2022 | The Auth Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with local access to obtain administrative usernames and passwords for the affected system. Affected… | ||
| CVE-2022-25212 | — | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials. | |
| CVE-2022-25211 | — | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials. | |
| CVE-2022-25209 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | ||
| CVE-2022-25208 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response. | ||
| CVE-2022-25207 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response. | ||
| CVE-2022-25206 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials. | ||
| CVE-2022-25205 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance. | ||
| CVE-2022-25200 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||
| CVE-2022-25199 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials. | ||
| CVE-2022-25198 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials. | ||
| CVE-2022-25194 | — | Hig | 0.50 | 8.8 | 0.01 | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified URL server using attacker-specified credentials. | |
| CVE-2022-25192 | — | Hig | 0.50 | 8.8 | 0.01 | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| CVE-2022-25183 | Hig | 0.50 | 8.8 | 0.02 | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins… | ||
| CVE-2022-25182 | Hig | 0.50 | 8.8 | 0.02 | Feb 15, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller JVM using specially crafted library names if a global Pipeline… | ||
| CVE-2022-25181 | Hig | 0.50 | 8.8 | 0.02 | Feb 15, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM through crafted SCM contents, if a global… | ||
| CVE-2022-25175 | — | Hig | 0.50 | 8.8 | 0.01 | Feb 15, 2022 | Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents. | |
| CVE-2022-25174 | Hig | 0.50 | 8.8 | 0.01 | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM… | ||
| CVE-2022-25173 | Hig | 0.50 | 8.8 | 0.01 | Feb 15, 2022 | Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the… | ||
| CVE-2022-24226 | Hig | 0.49 | 7.5 | 0.02 | Feb 15, 2022 | Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php. | ||
| CVE-2022-23604 | Hig | 0.00 | 8.8 | 0.01 | Feb 15, 2022 | x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderation. A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users… | ||
| CVE-2022-21698 | — | Hig | 0.00 | 7.5 | 0.06 | Feb 15, 2022 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through… | |
| CVE-2021-43734 | Hig | 0.50 | 7.5 | 0.11 | Feb 15, 2022 | kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host. | ||
| CVE-2021-42712 | Hig | 0.51 | 7.8 | 0.00 | Feb 15, 2022 | Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | ||
| CVE-2021-41552 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection. | ||
| CVE-2022-23384 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2022 | YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add | ||
| CVE-2022-23317 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2022 | CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL. | ||
| CVE-2022-0588 | Hig | 0.39 | 7.1 | 0.01 | Feb 15, 2022 | Missing Authorization in Packagist librenms/librenms prior to 22.2.0. | ||
| CVE-2021-43940 | Hig | 0.51 | 7.8 | 0.00 | Feb 15, 2022 | Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence… | ||
| CVE-2022-0580 | Hig | 0.39 | 7.1 | 0.01 | Feb 14, 2022 | Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0. | ||
| CVE-2022-23410 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2022 | AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be… | ||
| CVE-2021-46462 | Hig | 0.00 | 7.5 | 0.02 | Feb 14, 2022 | njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c. | ||
| CVE-2019-25057 | — | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2022 | In Corda before 4.1, the meaning of serialized data can be modified via an attacker-controlled CustomSerializer. | |
| CVE-2021-45348 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2022 | An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash). | ||
| CVE-2019-16864 | Hig | 0.58 | 8.8 | 0.08 | Feb 14, 2022 | CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM. | ||
| CVE-2022-25150 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2022 | In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges. | ||
| CVE-2021-45347 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2022 | An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password. | ||
| CVE-2022-22854 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2022 | An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via accessing and editing the user list. | ||
| CVE-2021-45392 | Hig | 0.50 | 7.5 | 0.12 | Feb 14, 2022 | A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service. | ||
| CVE-2021-46371 | Hig | 0.49 | 7.5 | 0.04 | Feb 14, 2022 | antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information. | ||
| CVE-2021-45421 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2022 | Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or… | ||
| CVE-2022-0572 | Hig | 0.02 | 7.8 | 0.27 | Feb 14, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0565 | Hig | 0.42 | 7.6 | 0.01 | Feb 14, 2022 | Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1. | ||
| CVE-2022-0214 | Hig | 0.49 | 7.5 | 0.02 | Feb 14, 2022 | The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog | ||
| CVE-2022-0190 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2022 | The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action. | ||
| CVE-2021-45444 | Hig | 0.51 | 7.8 | 0.02 | Feb 14, 2022 | In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion. | ||
| CVE-2022-22765 | Hig | 0.52 | 8.0 | 0.00 | Feb 12, 2022 | BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally… | ||
| CVE-2022-0311 | Hig | 0.57 | 8.8 | 0.01 | Feb 12, 2022 | Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. |
- risk 0.51cvss 7.8epss 0.00
Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
- risk 0.51cvss 7.8epss 0.00
Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.
- risk 0.55cvss 8.4epss 0.00
The Auth Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with local access to obtain administrative usernames and passwords for the affected system. Affected…
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.
- risk 0.57cvss 8.8epss 0.01
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials.
- risk 0.57cvss 8.8epss 0.01
Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- risk 0.57cvss 8.8epss 0.01
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
- risk 0.57cvss 8.8epss 0.01
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- risk 0.57cvss 8.8epss 0.01
A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
- risk 0.50cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified URL server using attacker-specified credentials.
- risk 0.50cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- risk 0.50cvss 8.8epss 0.02
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins…
- risk 0.50cvss 8.8epss 0.02
A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller JVM using specially crafted library names if a global Pipeline…
- risk 0.50cvss 8.8epss 0.02
A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM through crafted SCM contents, if a global…
- risk 0.50cvss 8.8epss 0.01
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
- risk 0.50cvss 8.8epss 0.01
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM…
- risk 0.50cvss 8.8epss 0.01
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the…
- risk 0.49cvss 7.5epss 0.02
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
- risk 0.00cvss 8.8epss 0.01
x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderation. A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users…
- risk 0.00cvss 7.5epss 0.06
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through…
- risk 0.50cvss 7.5epss 0.11
kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.
- risk 0.51cvss 7.8epss 0.00
Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
- risk 0.57cvss 8.8epss 0.01
CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
- risk 0.57cvss 8.8epss 0.01
YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
- risk 0.49cvss 7.5epss 0.01
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
- risk 0.39cvss 7.1epss 0.01
Missing Authorization in Packagist librenms/librenms prior to 22.2.0.
- risk 0.51cvss 7.8epss 0.00
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence…
- risk 0.39cvss 7.1epss 0.01
Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
- risk 0.51cvss 7.8epss 0.00
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be…
- risk 0.00cvss 7.5epss 0.02
njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c.
- risk 0.49cvss 7.5epss 0.01
In Corda before 4.1, the meaning of serialized data can be modified via an attacker-controlled CustomSerializer.
- risk 0.49cvss 7.5epss 0.01
An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).
- risk 0.58cvss 8.8epss 0.08
CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.
- risk 0.51cvss 7.8epss 0.00
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.
- risk 0.49cvss 7.5epss 0.01
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.
- risk 0.57cvss 8.8epss 0.01
An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via accessing and editing the user list.
- risk 0.50cvss 7.5epss 0.12
A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.
- risk 0.49cvss 7.5epss 0.04
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
- risk 0.49cvss 7.5epss 0.01
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or…
- risk 0.02cvss 7.8epss 0.27
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.42cvss 7.6epss 0.01
Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
- risk 0.49cvss 7.5epss 0.02
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
- risk 0.57cvss 8.8epss 0.01
The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.
- risk 0.51cvss 7.8epss 0.02
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
- risk 0.52cvss 8.0epss 0.00
BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally…
- risk 0.57cvss 8.8epss 0.01
Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.