VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1098 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2021-40904

checkmk

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-25523

typesetter

TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2022-1040

Sophos Firewall

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2021-46064

irfanview

IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-45757

rt-ac68u firmware, rt-ac68u

ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2021-45756

rt-ac68u firmware, rt-ac68u

Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-23352

bigant server

An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-23349

bigant server

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

The CVSS severity warrants an early asset and exposure review.
PriorityHigh
CVE-2022-23347

bigant server

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2022-23346

bigant server

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-23345

bigant server

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

The CVSS severity warrants an early asset and exposure review.