Vulnerabilities in unspecified

259 results
Vexday analysis

Com 259 CVEs catalogadas e nenhuma registrada em exploração ativa no CISA KEV, este conjunto apresenta taxa de exploração abaixo da média geral do catálogo. Ainda assim, o score EPSS de 0,5366 associado à CVE-2018-8021 — a vulnerabilidade de maior risco atual no conjunto — indica probabilidade não trivial de exploração, merecendo atenção mesmo na ausência de exploração confirmada. A falha mais recorrente é classificada como CWE-707, relacionada a problemas de neutralização inadequada de dados, e há duas vulnerabilidades com prova de conceito pública disponível, o que eleva o risco potencial mesmo sem incidentes registrados. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente no perfil de exposição, mas a presença de PoCs públicas recomenda monitoramento contínuo.

CVE-2022-4561LOWSemanticDrilldown Extension GET Parameter SDBrowseDataPage.php printFilterLine cross site scriptingEPSS 0.4%CVE-2022-4377LOWS-CMS Contact Information Page cross site scriptingEPSS 0.4%CVE-2022-4249LOWMovie Ticket Booking System POST Request cross site scriptingEPSS 0.4%CVE-2022-23040Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aEPSS 0.4%CVE-2022-23036Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aEPSS 0.4%CVE-2022-23041Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aEPSS 0.4%CVE-2022-23038Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aEPSS 0.4%CVE-2021-4268MEDIUMphpRedisAdmin cross-site request forgeryEPSS 0.4%CVE-2022-23039Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aEPSS 0.4%CVE-2021-4270LOWImprint CMS ViewHelpers.cs SearchForm cross site scriptingEPSS 0.3%CVE-2022-3978MEDIUMNodeBB abort cross-site request forgeryEPSS 0.3%CVE-2022-23037Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aEPSS 0.3%CVE-2017-20102MEDIUMAlbum Lock getImage path traversalEPSS 0.3%CVE-2020-36623MEDIUMPengu index.js runApp cross-site request forgeryEPSS 0.3%CVE-2022-4013MEDIUMHospital Management Center appointment.php cross-site request forgeryEPSS 0.2%CVE-2022-23042Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the text explains which aEPSS 0.2%CVE-2022-4641LOWpig-vector LogisticRegression.java LogisticRegression temp fileEPSS 0.2%CVE-2022-3967MEDIUMVesta Control Panel sed main.sh argument injectionEPSS 0.2%CVE-2022-4014MEDIUMFeehiCMS Post My Comment Tab cross-site request forgeryEPSS 0.2%