| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0198 | — | Hig | 0.39 | 7.1 | 0.01 | Jan 13, 2022 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference | |
| CVE-2022-0197 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2022-0196 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-43860 | Hig | 0.00 | 8.2 | 0.01 | Jan 12, 2022 | Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the… | ||
| CVE-2022-23118 | Hig | 0.57 | 8.8 | 0.02 | Jan 12, 2022 | Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller. | ||
| CVE-2022-23117 | Hig | 0.00 | 7.5 | 0.01 | Jan 12, 2022 | Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller. | ||
| CVE-2022-23116 | Hig | 0.49 | 7.5 | 0.01 | Jan 12, 2022 | Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method. | ||
| CVE-2022-23107 | Hig | 0.00 | 8.1 | 0.02 | Jan 12, 2022 | Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system. | ||
| CVE-2022-20619 | Hig | 0.39 | 7.1 | 0.01 | Jan 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials… | ||
| CVE-2022-20617 | Hig | 0.50 | 8.8 | 0.02 | Jan 12, 2022 | Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM… | ||
| CVE-2021-42559 | Hig | 0.57 | 8.8 | 0.02 | Jan 12, 2022 | An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is… | ||
| CVE-2021-41597 | Hig | 0.57 | 8.8 | 0.01 | Jan 12, 2022 | SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive. | ||
| CVE-2022-21676 | Hig | 0.42 | 7.5 | 0.03 | Jan 12, 2022 | Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the… | ||
| CVE-2021-42562 | Hig | 0.53 | 8.1 | 0.01 | Jan 12, 2022 | An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users. | ||
| CVE-2021-42561 | Hig | 0.59 | 8.8 | 0.20 | Jan 12, 2022 | An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current… | ||
| CVE-2021-42560 | Hig | 0.57 | 8.8 | 0.02 | Jan 12, 2022 | An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery,… | ||
| CVE-2021-36417 | Hig | 0.51 | 7.8 | 0.01 | Jan 12, 2022 | A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file. | ||
| CVE-2022-0015 | Hig | 0.51 | 7.8 | 0.00 | Jan 12, 2022 | A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex… | ||
| CVE-2021-45445 | Hig | 0.49 | 7.5 | 0.01 | Jan 12, 2022 | Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop. | ||
| CVE-2021-44652 | Hig | 0.51 | 7.8 | 0.03 | Jan 12, 2022 | Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component. | ||
| CVE-2021-44651 | Hig | 0.58 | 8.8 | 0.05 | Jan 12, 2022 | Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175. | ||
| CVE-2021-4080 | Hig | 0.50 | 8.8 | 0.01 | Jan 12, 2022 | crater is vulnerable to Unrestricted Upload of File with Dangerous Type | ||
| CVE-2021-44650 | Hig | 0.47 | 7.2 | 0.05 | Jan 12, 2022 | Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components. | ||
| CVE-2021-44648 | Hig | 0.57 | 8.8 | 0.02 | Jan 12, 2022 | GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12. | ||
| CVE-2021-3852 | Hig | 0.00 | 7.5 | 0.01 | Jan 12, 2022 | growi is vulnerable to Authorization Bypass Through User-Controlled Key | ||
| CVE-2022-21646 | Hig | 0.46 | 8.1 | 0.01 | Jan 11, 2022 | SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as… | ||
| CVE-2021-43999 | Hig | 0.57 | 8.8 | 0.02 | Jan 11, 2022 | Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user. | ||
| CVE-2022-21932 | Hig | 0.49 | 7.6 | 0.01 | Jan 11, 2022 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | ||
| CVE-2022-21922 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2022-21920 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-21919 | Hig | 0.58 | 7.0 | 0.03 | KEV | Jan 11, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2022-21917 | Hig | 0.51 | 7.8 | 0.04 | Jan 11, 2022 | HEVC Video Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-21916 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-21914 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | ||
| CVE-2022-21912 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | DirectX Graphics Kernel Remote Code Execution Vulnerability | ||
| CVE-2022-21911 | Hig | 0.49 | 7.5 | 0.03 | Jan 11, 2022 | .NET Framework Denial of Service Vulnerability | ||
| CVE-2022-21910 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Microsoft Cluster Port Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-21908 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2022-21904 | Hig | 0.49 | 7.5 | 0.04 | Jan 11, 2022 | Windows GDI Information Disclosure Vulnerability | ||
| CVE-2022-21903 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows GDI Elevation of Privilege Vulnerability | ||
| CVE-2022-21902 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2022-21898 | Hig | 0.51 | 7.8 | 0.02 | Jan 11, 2022 | DirectX Graphics Kernel Remote Code Execution Vulnerability | ||
| CVE-2022-21897 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-21896 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2022-21895 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability | ||
| CVE-2022-21893 | Hig | 0.53 | 8.0 | 0.07 | Jan 11, 2022 | Remote Desktop Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-21891 | Hig | 0.50 | 7.6 | 0.02 | Jan 11, 2022 | Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | ||
| CVE-2022-21890 | Hig | 0.49 | 7.5 | 0.03 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | ||
| CVE-2022-21889 | Hig | 0.49 | 7.5 | 0.03 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | ||
| CVE-2022-21888 | Hig | 0.51 | 7.8 | 0.03 | Jan 11, 2022 | Windows Modern Execution Server Remote Code Execution Vulnerability |
- risk 0.39cvss 7.1epss 0.01
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.2epss 0.01
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…
- risk 0.57cvss 8.8epss 0.02
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.
- risk 0.00cvss 7.5epss 0.01
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
- risk 0.49cvss 7.5epss 0.01
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
- risk 0.00cvss 8.1epss 0.02
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.
- risk 0.39cvss 7.1epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…
- risk 0.50cvss 8.8epss 0.02
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM…
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is…
- risk 0.57cvss 8.8epss 0.01
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
- risk 0.42cvss 7.5epss 0.03
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the…
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.
- risk 0.59cvss 8.8epss 0.20
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current…
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery,…
- risk 0.51cvss 7.8epss 0.01
A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file.
- risk 0.51cvss 7.8epss 0.00
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex…
- risk 0.49cvss 7.5epss 0.01
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
- risk 0.51cvss 7.8epss 0.03
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
- risk 0.58cvss 8.8epss 0.05
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
- risk 0.50cvss 8.8epss 0.01
crater is vulnerable to Unrestricted Upload of File with Dangerous Type
- risk 0.47cvss 7.2epss 0.05
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
- risk 0.57cvss 8.8epss 0.02
GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.
- risk 0.00cvss 7.5epss 0.01
growi is vulnerable to Authorization Bypass Through User-Controlled Key
- risk 0.46cvss 8.1epss 0.01
SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as…
- risk 0.57cvss 8.8epss 0.02
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.
- risk 0.49cvss 7.6epss 0.01
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
- risk 0.57cvss 8.8epss 0.03
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.58cvss 7.0epss 0.03
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
HEVC Video Extensions Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
DirectX Graphics Kernel Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.03
.NET Framework Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows GDI Information Disclosure Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows GDI Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
DirectX Graphics Kernel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.53cvss 8.0epss 0.07
Remote Desktop Protocol Remote Code Execution Vulnerability
- risk 0.50cvss 7.6epss 0.02
Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.03
Windows Modern Execution Server Remote Code Execution Vulnerability