CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-11101

    Last Modified: 14 Apr 2025

    Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.

    Published: 26 Dec 2022
    6.1
    Medium

    CVE-2021-30134

    Last Modified: 14 Apr 2025

    php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

    Published: 26 Dec 2022
    6.5
    Medium

    CVE-2019-18177

    Last Modified: 14 Apr 2025

    In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2019-19030

    Last Modified: 14 Apr 2025

    Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

    Published: 26 Dec 2022
    7.8
    High

    CVE-2019-19705

    Last Modified: 14 Apr 2025

    Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.

    Published: 26 Dec 2022
    7.5
    High

    CVE-2021-35951

    Last Modified: 14 Apr 2025

    fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious firmware update via BLE and brick the device.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2021-35952

    Last Modified: 14 Apr 2025

    fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to change the time, date, and month via Bluetooth LE Characteristics on handle 0x0017.

    Published: 26 Dec 2022
    7.5
    High

    CVE-2021-35953

    Last Modified: 14 Apr 2025

    fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device outage) via crafted choices of the last three bytes of a characteristic value.

    Published: 26 Dec 2022
    6.5
    Medium

    CVE-2021-39369

    Last Modified: 14 Apr 2025

    In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

    Published: 26 Dec 2022
    7.5
    High

    CVE-2021-44758

    Last Modified: 14 Apr 2025

    Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2021-44854

    Last Modified: 14 Apr 2025

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.

    Published: 26 Dec 2022
    9.8
    Critical

    CVE-2021-45466

    Last Modified: 14 Apr 2025

    In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.

    Published: 26 Dec 2022
    9.8
    Critical

    CVE-2021-45467

    Last Modified: 12 Apr 2025

    In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.

    Published: 26 Dec 2022
    9.8
    Critical

    CVE-2022-24117

    Last Modified: 12 Apr 2025

    Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

    Published: 26 Dec 2022
    8.8
    High

    CVE-2020-28191

    Last Modified: 14 Apr 2025

    The console in Togglz before 2.9.4 allows CSRF.

    Published: 26 Dec 2022
    7.4
    High

    CVE-2022-26964

    Last Modified: 14 Apr 2025

    Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.

    Published: 26 Dec 2022
    6.1
    Medium

    CVE-2022-31469

    Last Modified: 14 Apr 2025

    OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.

    Published: 26 Dec 2022
    6.1
    Medium

    CVE-2022-36664

    Last Modified: 14 Apr 2025

    Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.

    Published: 26 Dec 2022
    6.1
    Medium

    CVE-2022-37307

    Last Modified: 14 Apr 2025

    OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.

    Published: 26 Dec 2022
    6.1
    Medium

    CVE-2022-37308

    Last Modified: 14 Apr 2025

    OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2022-37311

    Last Modified: 14 Apr 2025

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2022-37313

    Last Modified: 14 Apr 2025

    OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

    Published: 26 Dec 2022
    7.5
    High

    CVE-2021-35065

    Last Modified: 14 Apr 2025

    The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

    Published: 26 Dec 2022
    8.1
    High

    CVE-2021-35954

    Last Modified: 14 Apr 2025

    fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, flash custom malicious firmware, and brick the device via the Serial Wire Debug (SWD) feature.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2022-41765

    Last Modified: 14 Apr 2025

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.

    Published: 26 Dec 2022
    5.5
    Medium

    CVE-2021-43395

    Last Modified: 14 Apr 2025

    An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.

    Published: 26 Dec 2022
    5.4
    Medium

    CVE-2021-44855

    Last Modified: 14 Apr 2025

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2021-44856

    Last Modified: 14 Apr 2025

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by AbuseFilter can be created via Special:ChangeContentModel due to the mishandling of the EditFilterMergedContent hook return value.

    Published: 26 Dec 2022
    9.8
    Critical

    CVE-2022-24116

    Last Modified: 12 Apr 2025

    Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

    Published: 26 Dec 2022
    9.1
    Critical

    CVE-2022-24118

    Last Modified: 12 Apr 2025

    Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

    Published: 26 Dec 2022
    9.8
    Critical

    CVE-2022-24119

    Last Modified: 12 Apr 2025

    Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.

    Published: 26 Dec 2022
    9.8
    Critical

    CVE-2022-26969

    Last Modified: 14 Apr 2025

    In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.

    Published: 26 Dec 2022
    5.4
    Medium

    CVE-2022-29853

    Last Modified: 14 Apr 2025

    OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

    Published: 26 Dec 2022
    7.8
    High

    CVE-2022-30260

    Last Modified: 21 Nov 2024

    Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.

    Published: 26 Dec 2022
    6.1
    Medium

    CVE-2022-37310

    Last Modified: 14 Apr 2025

    OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2022-37312

    Last Modified: 14 Apr 2025

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.

    Published: 26 Dec 2022
    5.3
    Medium

    CVE-2022-41767

    Last Modified: 14 Apr 2025

    An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.

    Published: 26 Dec 2022
    4.6
    Medium

    CVE-2022-24120

    Last Modified: 12 Apr 2025

    Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

    Published: 26 Dec 2022
    5.4
    Medium

    CVE-2022-29852

    Last Modified: 14 Apr 2025

    OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.

    Published: 26 Dec 2022
    6.5
    Medium

    CVE-2018-16135

    Last Modified: 14 Apr 2025

    The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

    Published: 26 Dec 2022
    4.3
    Medium

    CVE-2021-4280

    Last Modified: 14 Apr 2025

    A vulnerability was found in styler_praat_scripts. It has been classified as problematic. Affected is an unknown function of the file file_segmenter.praat of the component Slash Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The name of the patch is 0cad44aa4a3eb0ecdba071c10eaff16023d8b35f. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216780.

    Published: 25 Dec 2022
    4.3
    Medium

    CVE-2022-4741

    Last Modified: 21 Nov 2024

    A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertDocx/ConvertODT/ConvertPages/ConvertXML/XMLToText. The manipulation leads to uncontrolled memory allocation. The attack may be initiated remotely. Upgrading to version 1.2.1 is able to address this issue. The name of the patch is 42bcff666855ab978e67a9041d0cdea552f20301. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216779.

    Published: 25 Dec 2022
    6.3
    Medium

    CVE-2021-4279

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 is able to address this issue. The name of the patch is 7ad6af41eabb2d799f698740a91284d762c955c9. It is recommended to upgrade the affected component. VDB-216778 is the identifier assigned to this vulnerability.

    Published: 25 Dec 2022
    6.3
    Medium

    CVE-2020-36632

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to initiate the attack remotely. Upgrading to version 5.0.1 is able to address this issue. The name of the patch is 20ef0ef55dfa028caddaedbcb33efbdb04d18e13. It is recommended to upgrade the affected component. The identifier VDB-216777 was assigned to this vulnerability.

    Published: 25 Dec 2022
    3.5
    Low

    CVE-2022-4740

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the function setWatermarkAttribute of the file /picturesPreview. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216776.

    Published: 25 Dec 2022
    7.3
    High

    CVE-2022-4739

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in SourceCodester School Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Admin Login. The manipulation leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-216775.

    Published: 25 Dec 2022
    4.3
    Medium

    CVE-2022-4738

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is an unknown function of the file index.php?page=users of the component User Registration Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack remotely. VDB-216774 is the identifier assigned to this vulnerability.

    Published: 25 Dec 2022
    7.3
    High

    CVE-2022-4737

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The identifier VDB-216773 was assigned to this vulnerability.

    Published: 25 Dec 2022
    6.3
    Medium

    CVE-2020-36631

    Last Modified: 21 Nov 2024

    A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerability affects the function update_profile of the file gamespy/gs_database.py. The manipulation of the argument firstname/lastname leads to sql injection. The attack can be initiated remotely. The name of the patch is f70eb21394f75019886fbc2fb536de36161ba422. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216772.

    Published: 25 Dec 2022
    5.5
    Medium

    CVE-2020-36630

    Last Modified: 21 Nov 2024

    A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.php. The manipulation of the argument limit/offset leads to sql injection. Upgrading to version 14.0.5.21 is able to address this issue. The name of the patch is f1a9eea2dfff30fb99d825bac194a676a82b9ec8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216771.

    Published: 25 Dec 2022