VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1096 of 1178 · EPSS data 2026.08.06
ReviewCritical
CVE-2022-28397

ghost

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-27262

skipper

An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2022-27260

buttercms

An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2022-22954

VMware Workspace ONE Access and Identity Manager

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2021-37292

4st l-bems

An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2021-37291

4st l-bems

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-40219

bolt cms

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-26607

baigo cms

A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-26251

synaman

The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-26250

synaman

Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-26281

bigant server

BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

The CVSS severity warrants an early asset and exposure review.