CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2014-125049

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in typcn Blogile. Affected is the function getNav of the file server.js. The manipulation of the argument query leads to sql injection. The name of the patch is cfec31043b562ffefe29fe01af6d3c5ed1bf8f7d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217560. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 6 Jan 2023
    6.3
    Medium

    CVE-2014-125048

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in kassi xingwall. This issue affects some unknown processing of the file app/controllers/oauth.js. The manipulation leads to session fixiation. The patch is named e9f0d509e1408743048e29d9c099d36e0e1f6ae7. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217559.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2019-25099

    Last Modified: 10 Apr 2025

    A vulnerability classified as critical was found in Arthmoor QSF-Portal. This vulnerability affects unknown code of the file index.php. The manipulation of the argument a leads to path traversal. The patch is identified as ea4f61e23ecb83247d174bc2e2cbab521c751a7d. It is recommended to apply a patch to fix this issue. VDB-217558 is the identifier assigned to this vulnerability.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2014-125047

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in tbezman school-store. This affects an unknown part. The manipulation leads to sql injection. The identifier of the patch is 2957fc97054216d3a393f1775efd01ae2b072001. It is recommended to apply a patch to fix this issue. The identifier VDB-217557 was assigned to this vulnerability.

    Published: 6 Jan 2023
    4.6
    Medium

    CVE-2022-4879

    Last Modified: 28 May 2025

    A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named 6880971bd3d73d942384aff62d53058c206ce644. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217555.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2018-25066

    Last Modified: 21 Nov 2024

    A vulnerability was found in PeterMu nodebatis up to 2.1.x. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection. Upgrading to version 2.2.0 is able to address this issue. The patch is identified as 6629ff5b7e3d62ad8319007a54589ec1f62c7c35. It is recommended to upgrade the affected component. VDB-217554 is the identifier assigned to this vulnerability.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2020-36642

    Last Modified: 10 Apr 2025

    A vulnerability was found in trampgeek jobe up to 1.6.x and classified as critical. This issue affects the function run_in_sandbox of the file application/libraries/LanguageTask.php. The manipulation leads to command injection. Upgrading to version 1.7.0 is able to address this issue. The identifier of the patch is 8f43daf50c943b98eaf0c542da901a4a16e85b02. It is recommended to upgrade the affected component. The identifier VDB-217553 was assigned to this vulnerability.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2015-10017

    Last Modified: 21 Nov 2024

    A vulnerability has been found in HPI-Information-Systems ProLOD and classified as critical. This vulnerability affects unknown code. The manipulation of the argument this leads to sql injection. The name of the patch is 3f710905458d49c77530bd3cbcd8960457566b73. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217552.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2014-125046

    Last Modified: 10 Apr 2025

    A vulnerability, which was classified as critical, was found in Seiji42 cub-scout-tracker. This affects an unknown part of the file databaseAccessFunctions.js. The manipulation leads to sql injection. The patch is named b4bc1a328b1f59437db159f9d136d9ed15707e31. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217551.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2015-10016

    Last Modified: 25 Nov 2024

    A vulnerability, which was classified as critical, has been found in jeff-kelley opensim-utils. Affected by this issue is the function DatabaseForRegion of the file regionscrits.php. The manipulation of the argument region leads to sql injection. The patch is identified as c29e5c729a833a29dbf5b1e505a0553fe154575e. It is recommended to apply a patch to fix this issue. VDB-217550 is the identifier assigned to this vulnerability.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2016-15011

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse of the file dssp-client/src/main/java/be/e_contract/dssp/client/SignResponseVerifier.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.2 is able to address this issue. The identifier of the patch is ec4238349691ec66dd30b416ec6eaab02d722302. It is recommended to upgrade the affected component. The identifier VDB-217549 was assigned to this vulnerability.

    Published: 6 Jan 2023
    5.5
    Medium

    CVE-2022-4878

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/common/app/utils/common/ZipUtil.java of the component ZIP Handler. The manipulation leads to path traversal. Upgrading to version 3.7.5-alpha is able to address this issue. The name of the patch is 2b42519f309d8164e8811392770ce604cdabb5da. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217548.

    Published: 6 Jan 2023
    8.4
    High

    CVE-2022-40520

    Last Modified: 9 Apr 2025

    Memory corruption due to stack-based buffer overflow in Core

    Published: 6 Jan 2023
    6.8
    Medium

    CVE-2022-40519

    Last Modified: 9 Apr 2025

    Information disclosure due to buffer overread in Core

    Published: 6 Jan 2023
    6.8
    Medium

    CVE-2022-40518

    Last Modified: 9 Apr 2025

    Information disclosure due to buffer overread in Core

    Published: 6 Jan 2023
    8.4
    High

    CVE-2022-40517

    Last Modified: 9 Apr 2025

    Memory corruption in core due to stack-based buffer overflow

    Published: 6 Jan 2023
    8.4
    High

    CVE-2022-40516

    Last Modified: 9 Apr 2025

    Memory corruption in Core due to stack-based buffer overflow.

    Published: 6 Jan 2023
    8.4
    High

    CVE-2022-33300

    Last Modified: 9 Apr 2025

    Memory corruption in Automotive Android OS due to improper input validation.

    Published: 6 Jan 2023
    7.5
    High

    CVE-2022-33299

    Last Modified: 9 Apr 2025

    Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.

    Published: 6 Jan 2023
    7.5
    High

    CVE-2022-33290

    Last Modified: 9 Apr 2025

    Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed.

    Published: 6 Jan 2023
    7.5
    High

    CVE-2022-33286

    Last Modified: 9 Apr 2025

    Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.

    Published: 6 Jan 2023
    7.5
    High

    CVE-2022-33285

    Last Modified: 9 Apr 2025

    Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.

    Published: 6 Jan 2023
    8.2
    High

    CVE-2022-33284

    Last Modified: 9 Apr 2025

    Information disclosure due to buffer over-read in WLAN while parsing BTM action frame.

    Published: 6 Jan 2023
    8.2
    High

    CVE-2022-33283

    Last Modified: 9 Apr 2025

    Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check.

    Published: 6 Jan 2023
    8.4
    High

    CVE-2022-33276

    Last Modified: 9 Apr 2025

    Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.

    Published: 6 Jan 2023
    8.4
    High

    CVE-2022-33274

    Last Modified: 9 Apr 2025

    Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication.

    Published: 6 Jan 2023
    5.9
    Medium

    CVE-2022-33266

    Last Modified: 9 Apr 2025

    Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content.

    Published: 6 Jan 2023
    7.3
    High

    CVE-2022-33265

    Last Modified: 9 Apr 2025

    Memory corruption due to information exposure in Powerline Communication Firmware while sending different MMEs from a single, unassociated device.

    Published: 6 Jan 2023
    8.2
    High

    CVE-2022-33255

    Last Modified: 9 Apr 2025

    Information disclosure due to buffer over-read in Bluetooth HOST while processing GetFolderItems and GetItemAttribute Cmds from peer device.

    Published: 6 Jan 2023
    7.5
    High

    CVE-2022-33253

    Last Modified: 9 Apr 2025

    Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.

    Published: 6 Jan 2023
    8.2
    High

    CVE-2022-33252

    Last Modified: 9 Apr 2025

    Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.

    Published: 6 Jan 2023
    9.3
    Critical

    CVE-2022-33219

    Last Modified: 9 Apr 2025

    Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.

    Published: 6 Jan 2023
    8.2
    High

    CVE-2022-33218

    Last Modified: 9 Apr 2025

    Memory corruption in Automotive due to improper input validation.

    Published: 6 Jan 2023
    8.1
    High

    CVE-2022-25746

    Last Modified: 9 Apr 2025

    Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.

    Published: 6 Jan 2023
    6.2
    Medium

    CVE-2022-25725

    Last Modified: 9 Apr 2025

    Denial of service in MODEM due to improper pointer handling

    Published: 6 Jan 2023
    6
    Medium

    CVE-2022-25722

    Last Modified: 9 Apr 2025

    Information exposure in DSP services due to improper handling of freeing memory

    Published: 6 Jan 2023
    6.7
    Medium

    CVE-2022-25721

    Last Modified: 9 Apr 2025

    Memory corruption in video driver due to type confusion error during video playback

    Published: 6 Jan 2023
    7.4
    High

    CVE-2022-25923

    Last Modified: 10 Apr 2025

    Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

    Published: 6 Jan 2023
    6.7
    Medium

    CVE-2022-25717

    Last Modified: 9 Apr 2025

    Memory corruption in display due to double free while allocating frame buffer memory

    Published: 6 Jan 2023
    6.7
    Medium

    CVE-2022-25716

    Last Modified: 9 Apr 2025

    Memory corruption in Multimedia Framework due to unsafe access to the data members

    Published: 6 Jan 2023
    6.7
    Medium

    CVE-2022-25715

    Last Modified: 9 Apr 2025

    Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields

    Published: 6 Jan 2023
    9.8
    Critical

    CVE-2022-22088

    Last Modified: 9 Apr 2025

    Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote

    Published: 6 Jan 2023
    4.6
    Medium

    CVE-2022-22079

    Last Modified: 9 Apr 2025

    Denial of service while processing fastboot flash command on mmc due to buffer over read

    Published: 6 Jan 2023
    5.4
    Medium

    CVE-2022-39072

    Last Modified: 10 Apr 2025

    There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.

    Published: 6 Jan 2023
    8.8
    High

    CVE-2022-42979

    Last Modified: 9 Apr 2025

    Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an account via a deep link.

    Published: 6 Jan 2023
    8.8
    High

    CVE-2022-44149

    Last Modified: 9 Apr 2025

    The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required

    Published: 6 Jan 2023
    7.5
    High

    CVE-2022-46761

    Last Modified: 9 Apr 2025

    The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.

    Published: 6 Jan 2023
    7.5
    High

    CVE-2021-46867

    Last Modified: 10 Apr 2025

    The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.

    Published: 6 Jan 2023
    7.5
    High

    CVE-2021-46868

    Last Modified: 10 Apr 2025

    The HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory access.

    Published: 6 Jan 2023
    6.1
    Medium

    CVE-2022-45911

    Last Modified: 9 Apr 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.

    Published: 6 Jan 2023