VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1092 of 1178 · EPSS data 2026.08.06
ReviewCritical
CVE-2022-24240

aceweb online portal

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-24239

aceweb online portal

ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2021-42872

ex1200t firmware, ex1200t

TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2022-30190

Microsoft Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation)

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2022-22675

Apple macOS

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVMedium
CVE-2022-22674

Apple macOS

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVMedium
CVE-2022-20821

Cisco IOS XR

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configurat...

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2022-27305

gibbon

Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-29333

powerdirector

A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-28944

msi package builder, network inventory

Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMC...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-30014

simple food website

Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-28932

dsl-g2452dg firmware, dsl-g2452dg

CVE-2022-28932 affects dsl-g2452dg firmware, dsl-g2452dg. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-30065

busybox, scalance sc622-2c firmware

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-29641

a3100r firmware, a3100r

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-29351

tiddlywiki5

An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.

The CVSS severity warrants an early asset and exposure review.