VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 17 hours ago
Reset
More filters (2)
Columns
Published from 2022-01-01Published to 2022-12-31
Overview 20 matches, all in RASP scope, all public PoC · 11 protected · 0 KEV · 2 CISA SSVC · 7 EPSS ≥ 0.5 · 0 disputed
20matches, all in RASP scope, all public PoC 11protected55.0% 0KEV0.0% 2CISA SSVC10.0% 7EPSS ≥ 0.535.0% 0disputed0.0%
Critical 7 35.0% High 9 45.0% Medium 4 20.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 10 50.0% Rule in development 0 0.0% Mitigation candidate 9 45.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 1 5.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 11 55.0% not blocked 9 45.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 20 100.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 0 0.0%
split by peak 4 / month
Unknown: 0None: 0Low: 0Medium: 4High: 9Critical: 7 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 1No fix identified: 0No exploit published: 0Mitigation candidate: 9Rule in development: 0Protected by RASP: 10 unrecorded: 0not established: 0not blocked: 9blocked by ARMR today: 11 No public exploit: 0Forecast only: 0Proof of concept only: 0Working exploit published: 20Exploited in the wild: 0 January 2022: 2 CVEs February 2022: 1 CVE March 2022: 2 CVEs April 2022: 4 CVEs May 2022: 4 CVEs June 2022: 1 CVE July 2022: 3 CVEs August 2022: 0 CVEs September 2022: 0 CVEs October 2022: 1 CVE November 2022: 1 CVE December 2022: 1 CVE
Jan 22Feb 22Mar 22Apr 22May 22Jun 22Jul 22Aug 22Sep 22Oct 22Nov 22Dec 22
20 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2022-4375 Critical 2022-12-09 Protected by RASP Working exploit published A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.2.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215196.
CVE-2022-42118 Medium 2022-11-15 Mitigation candidate Working exploit published A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
CVE-2022-42889 Critical 2022-10-13 Protected by RASP Working exploit published Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
CVE-2022-36883 High 2022-07-27 Mitigation candidate Working exploit published A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
CVE-2022-32430 High 2022-07-21 Mitigation candidate Working exploit published An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
CVE-2021-43116 High 2022-07-05 Mitigation candidate Working exploit published An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
CVE-2022-34305 Medium 2022-06-23 Protected by RASP Working exploit published In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
CVE-2022-31268 High 2022-05-21 Protected by RASP Working exploit published A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
CVE-2022-21500 High 2022-05-20 Protected by RASP Working exploit published Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. <br> <br>Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should refer to the Patch Availability Document for details. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2022-29885 High 2022-05-12 Mitigated by environment configuration Working exploit published The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
CVE-2021-40822 High 2022-05-02 Mitigation candidate Working exploit published GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
CVE-2021-31805 Critical 2022-04-12 Mitigation candidate Working exploit published The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
CVE-2022-24819 Medium 2022-04-08 Mitigation candidate Working exploit published XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.
CVE-2022-26585 Critical 2022-04-05 Protected by RASP Working exploit published Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
CVE-2021-44138 High 2022-04-04 Protected by RASP Working exploit published There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.
CVE-2021-20323 Medium 2022-03-25 Mitigation candidate Working exploit published A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
CVE-2022-23898 Critical 2022-03-03 Protected by RASP Working exploit published MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
CVE-2021-44521 Critical 2022-02-11 Protected by RASP Working exploit published When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.
CVE-2022-23944 Critical 2022-01-25 Mitigation candidate Working exploit published User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVE-2022-21371 High 2022-01-19 Protected by RASP Working exploit published Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).