CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-31468

    Last Modified: 9 May 2025

    OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.

    Published: 24 Oct 2022
    5.5
    Medium

    CVE-2022-38117

    Last Modified: 7 May 2025

    Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.

    Published: 24 Oct 2022
    —
    Unknown

    CVE-2022-3680

    Last Modified: 7 Nov 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 24 Oct 2022
    —
    Unknown

    CVE-2022-3678

    Last Modified: 7 Nov 2023

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 24 Oct 2022
    7.5
    High

    CVE-2022-43680

    Last Modified: 30 May 2025

    In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

    Published: 24 Oct 2022
    4.9
    Medium

    CVE-2021-44769

    Last Modified: 7 May 2025

    An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Denial-of-Service (DoS) condition which can only be reverted via a factory reset. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    5.5
    Medium

    CVE-2022-39836

    Last Modified: 7 May 2025

    An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.

    Published: 24 Oct 2022
    5.5
    Medium

    CVE-2022-39837

    Last Modified: 7 May 2025

    An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a NULL pointer dereference,

    Published: 24 Oct 2022
    7.8
    High

    CVE-2022-41796

    Last Modified: 7 May 2025

    Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 24 Oct 2022
    10
    Critical

    CVE-2021-26727

    Last Modified: 7 May 2025

    Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    10
    Critical

    CVE-2021-26728

    Last Modified: 21 Nov 2024

    Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    9.1
    Critical

    CVE-2021-26731

    Last Modified: 7 May 2025

    Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    10
    Critical

    CVE-2021-26730

    Last Modified: 7 May 2025

    A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    6.5
    Medium

    CVE-2021-26732

    Last Modified: 7 May 2025

    A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    5.3
    Medium

    CVE-2021-44467

    Last Modified: 7 May 2025

    A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrarily terminate active sessions of other users, causing a Denial-of-Service (DoS) condition, if an input parameter is correctly guessed. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    5.3
    Medium

    CVE-2021-45925

    Last Modified: 7 May 2025

    Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    9.1
    Critical

    CVE-2021-46848

    Last Modified: 7 May 2025

    GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

    Published: 24 Oct 2022
    —
    Unknown

    CVE-2021-46849

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29421. Reason: This candidate is a duplicate of CVE-2021-29421. Notes: All CVE users should reference CVE-2021-29421 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 24 Oct 2022
    7.8
    High

    CVE-2022-41973

    Last Modified: 21 Nov 2024

    multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.

    Published: 24 Oct 2022
    5.5
    Medium

    CVE-2022-43677

    Last Modified: 21 Nov 2024

    In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.

    Published: 24 Oct 2022
    6.5
    Medium

    CVE-2022-3676

    Last Modified: 7 May 2025

    In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.

    Published: 24 Oct 2022
    5.4
    Medium

    CVE-2022-40690

    Last Modified: 7 May 2025

    Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.

    Published: 24 Oct 2022
    9.8
    Critical

    CVE-2022-40984

    Last Modified: 7 May 2025

    Stack-based buffer overflow in WTViewerE series WTViewerE 761941 from 1.31 to 1.61 and WTViewerEfree from 1.01 to 1.52 allows an attacker to cause the product to crash by processing a long file name.

    Published: 24 Oct 2022
    6.5
    Medium

    CVE-2022-41799

    Last Modified: 7 May 2025

    Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.

    Published: 24 Oct 2022
    9.8
    Critical

    CVE-2021-42010

    Last Modified: 7 May 2025

    Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.

    Published: 24 Oct 2022
    5.8
    Medium

    CVE-2021-4228

    Last Modified: 5 May 2025

    Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connection. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.00.0.

    Published: 24 Oct 2022
    6.5
    Medium

    CVE-2021-44776

    Last Modified: 7 May 2025

    A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbitrarily change the security access rights to KVM and Virtual Media functionalities. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    5.8
    Medium

    CVE-2021-46279

    Last Modified: 7 May 2025

    Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attacks against users. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    7.2
    High

    CVE-2021-46850

    Last Modified: 7 May 2025

    myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.

    Published: 24 Oct 2022
    10
    Critical

    CVE-2021-26729

    Last Modified: 7 May 2025

    Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    5.3
    Medium

    CVE-2021-26733

    Last Modified: 7 May 2025

    A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) condition. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

    Published: 24 Oct 2022
    7.5
    High

    CVE-2022-41986

    Last Modified: 7 May 2025

    Information disclosure vulnerability in Android App 'IIJ SmartKey' versions prior to 2.1.4 allows an attacker to obtain a one-time password issued by the product under certain conditions.

    Published: 24 Oct 2022
    3.7
    Low

    CVE-2022-39314

    Last Modified: 30 Jan 2026

    Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code` or `password-reset` auth method with the `auth.methods` option or if you have enabled the `debug` option in production. By using two or more IP addresses and multiple login attempts, valid user accounts will lock, but invalid accounts will not, leading to account enumeration. This issue has been patched in versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1. If you cannot update immediately, you can work around the issue by setting the `auth.methods` option to `password`, which disables the code-based login and password reset forms.

    Published: 24 Oct 2022
    4.8
    Medium

    CVE-2022-36368

    Last Modified: 7 May 2025

    Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.

    Published: 24 Oct 2022
    9.8
    Critical

    CVE-2022-38580

    Last Modified: 7 May 2025

    Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

    Published: 24 Oct 2022
    9.8
    Critical

    CVE-2022-39305

    Last Modified: 22 Apr 2025

    Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 contain a file upload ability. The affected code fails to validate fileMd5 and fileName parameters, resulting in an arbitrary file being read. This issue is patched in 2.5.4b. There are no known workarounds.

    Published: 24 Oct 2022
    7.5
    High

    CVE-2022-39313

    Last Modified: 23 Apr 2025

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte range, resulting in a Denial of Service. This issue has been patched in versions 4.10.17, and 5.2.8. There are no known workarounds.

    Published: 24 Oct 2022
    6.5
    Medium

    CVE-2022-41797

    Last Modified: 7 May 2025

    Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

    Published: 24 Oct 2022
    7.8
    High

    CVE-2022-41974

    Last Modified: 21 Nov 2024

    multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

    Published: 24 Oct 2022
    7.8
    High

    CVE-2022-3977

    Last Modified: 8 Apr 2025

    A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This issue occurs when a user simultaneously calls DROPTAG ioctl and socket close happens, which could allow a local user to crash the system or potentially escalate their privileges on the system.

    Published: 23 Oct 2022
    6.6
    Medium

    CVE-2022-3628

    Last Modified: 8 Apr 2025

    A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device. This can allow a local user to crash the system or escalate their privileges.

    Published: 22 Oct 2022
    7.8
    High

    CVE-2023-3812

    Last Modified: 26 Feb 2026

    An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published: 22 Oct 2022
    6.4
    Medium

    CVE-2022-45888

    Last Modified: 3 Nov 2025

    An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.

    Published: 22 Oct 2022
    5.3
    Medium

    CVE-2022-34439

    Last Modified: 7 May 2025

    Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service and performance issue on that node.

    Published: 21 Oct 2022
    6.7
    Medium

    CVE-2022-34438

    Last Modified: 7 May 2025

    Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance mode clusters.

    Published: 21 Oct 2022
    6.7
    Medium

    CVE-2022-34437

    Last Modified: 7 May 2025

    Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentially exploit this vulnerability, leading to a full system compromise. This impacts compliance mode clusters.

    Published: 21 Oct 2022
    6.7
    Medium

    CVE-2022-31239

    Last Modified: 7 May 2025

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log files vulnerability. A privileged local user may potentially exploit this vulnerability, leading to disclosure of this sensitive data.

    Published: 21 Oct 2022
    7
    High

    CVE-2022-26870

    Last Modified: 7 May 2025

    Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unauthorized access upon successful exploit.

    Published: 21 Oct 2022
    4.3
    Medium

    CVE-2020-5355

    Last Modified: 7 May 2025

    The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.

    Published: 21 Oct 2022
    8.2
    High

    CVE-2022-27494

    Last Modified: 17 Apr 2025

    Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

    Published: 21 Oct 2022