VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1087 of 1178 · EPSS data 2026.08.06
ReviewCritical
CVE-2022-37053

tew733gr firmware, tew733gr

CVE-2022-37053 affects tew733gr firmware, tew733gr. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2022-36537

ZK Framework AuUploader

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2022-35192

dsl-3782 firmware, dsl-3782

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2022-36804

Atlassian Bitbucket Server and Data Center

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2022-32894

Apple iOS and macOS

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2022-32893

Apple iOS and macOS

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
PriorityCritical
CVE-2021-42627

dir-615 firmware, dir-615

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewCritical
CVE-2021-42232

archer a7 firmware, archer a7

TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on the router.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-35201

ac18 firmware, ac18

Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-35167

cloud print management

Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-36526

go-rt-ac750 firmware, go-rt-ac750

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-36524

go-rt-ac750 firmware, go-rt-ac750

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-36262

taocms

An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2022-37042

zimbra collaboration suite

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.