VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1090 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2022-24138

advanced systemcare

IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the genuine component with a malicious executable thus gaining code execution as a high privilege user (Low Privilege -> high integrity ADMIN).

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-25898

jsrsasign

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2020-21046

eagleget

A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as a SYSTEM privilege.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-21952

SUSE SUSE Manager Server 4.1, SUSE Manager Server 4.2, manager server

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-45025

ags-zena

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2021-45024

ags-zena

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-26173

jforum

JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2022-24562

iotransfer

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewCritical
CVE-2022-31384

directory management system

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-31383

directory management system

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-31382

directory management system

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

The CVSS severity warrants an early asset and exposure review.
PriorityHigh
CVE-2022-30023

hg9 firmware, hg9

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

FIRST EPSS indicates an elevated probability of exploitation.