VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 1101 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2022-24253

portfolio

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-24252

portfolio

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-24251

portfolio

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2022-25018

pluxml

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-42951

msol

A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new, specially crafted Algorithm and subsequently launch remote code execution with their desired result.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2022-25064

tl-wr840n firmware, tl-wr840n

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2022-25062

tl-wr840n firmware, tl-wr840n

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2022-25061

tl-wr840n firmware, tl-wr840n

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

FIRST EPSS indicates an elevated probability of exploitation.
PriorityCritical
CVE-2022-25060

tl-wr840n firmware, tl-wr840n

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewCritical
CVE-2021-42952

zepl

Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2022-23176

WatchGuard Firebox and XTM

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVCritical
CVE-2022-0543

Redis Debian-specific Redis Servers

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2021-20322

kernel, linux kernel, fedora

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2022-22916

o2oa

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2022-22914

ovidentia

An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal.

The CVSS severity warrants an early asset and exposure review.