VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1088 of 1178 · EPSS data 2026.08.06
ReviewCritical
CVE-2022-35293

SAP SE SAP Enable Now Manager, enable now manager

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2021-33643

libtar, openeuler, fedora

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2022-0028

Palo Alto Networks PAN-OS

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and,...

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2022-34713

Microsoft Windows

CVE-2022-34713 affects Microsoft Windows. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2022-36124

Apache Software Foundation Apache Avro, avro

It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2022-37434

CADRA, RUGGEDCOM ROX MX5000

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

FIRST EPSS indicates an elevated probability of exploitation.
ReviewCritical
CVE-2022-31321

bolt

The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2022-1364

Google Chromium V8

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewCritical
CVE-2022-35131

joplin

Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-24992

qr code generator

A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-29709

clink office

CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2022-1096

Google Chromium V8

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVCritical
CVE-2022-26138

Atlassian Confluence

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.