Show filters
181,112 Total Results
Displaying 91-100 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
High
CVE-2022-39952
Disclosure Date: February 16, 2023 (last updated February 24, 2025)
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.
4
Attacker Value
Very High
CVE-2022-24990
Disclosure Date: February 07, 2023 (last updated February 24, 2025)
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
4
Attacker Value
Moderate
CVE-2023-22952
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
4
Attacker Value
High
CVE-2022-2294
Disclosure Date: July 28, 2022 (last updated February 24, 2025)
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5
Attacker Value
High
CVE-2022-22972
Disclosure Date: May 20, 2022 (last updated November 29, 2024)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
5
Attacker Value
Very High
CVE-2022-27925
Disclosure Date: April 21, 2022 (last updated March 08, 2025)
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
5
Attacker Value
Very High
CVE-2022-29464
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.
5
Attacker Value
High
CVE-2022-21907
Disclosure Date: January 11, 2022 (last updated November 28, 2024)
HTTP Protocol Stack Remote Code Execution Vulnerability
5
Attacker Value
High
CVE-2022-21882
Disclosure Date: January 11, 2022 (last updated February 23, 2025)
Win32k Elevation of Privilege Vulnerability
5
Attacker Value
High
CVE-2021-42237
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
6