CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-36545

    Last Modified: 16 Dec 2025

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36544

    Last Modified: 16 Dec 2025

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36543

    Last Modified: 16 Dec 2025

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.

    Published: 26 Aug 2022
    6.5
    Medium

    CVE-2022-36542

    Last Modified: 16 Dec 2025

    An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.

    Published: 26 Aug 2022
    8.8
    High

    CVE-2022-2915

    Last Modified: 21 Nov 2024

    A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and earlier versions.

    Published: 26 Aug 2022
    —
    Unknown

    CVE-2022-38785

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2905. Reason: This candidate is a reservation duplicate of CVE-2022-2905. Notes: All CVE users should reference CVE-2022-2905 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Aug 2022
    8.8
    High

    CVE-2022-36529

    Last Modified: 21 Nov 2024

    Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at /framework/mod/db/DBMapper.xml.

    Published: 26 Aug 2022
    6.5
    Medium

    CVE-2022-36522

    Last Modified: 21 Nov 2024

    Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

    Published: 26 Aug 2022
    7.5
    High

    CVE-2022-0217

    Last Modified: 21 Nov 2024

    It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).

    Published: 26 Aug 2022
    5.4
    Medium

    CVE-2022-35714

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231116.

    Published: 26 Aug 2022
    8.8
    High

    CVE-2022-31773

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 228357.

    Published: 26 Aug 2022
    —
    Unknown

    CVE-2021-3691

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Aug 2022
    5.5
    Medium

    CVE-2021-4216

    Last Modified: 21 Nov 2024

    A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.

    Published: 26 Aug 2022
    8.8
    High

    CVE-2022-25625

    Last Modified: 21 Nov 2024

    A malicious unauthorized PAM user can access the administration configuration data and change the values.

    Published: 26 Aug 2022
    —
    Unknown

    CVE-2021-3627

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Aug 2022
    —
    Unknown

    CVE-2021-3651

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Aug 2022
    —
    Unknown

    CVE-2021-3913

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Aug 2022
    —
    Unknown

    CVE-2021-4215

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Aug 2022
    7.5
    High

    CVE-2022-36521

    Last Modified: 21 Nov 2024

    Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36681

    Last Modified: 21 Nov 2024

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36683

    Last Modified: 21 Nov 2024

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.

    Published: 26 Aug 2022
    6.5
    Medium

    CVE-2021-39394

    Last Modified: 21 Nov 2024

    mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add user accounts and modify user information.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36682

    Last Modified: 21 Nov 2024

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36680

    Last Modified: 21 Nov 2024

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36679

    Last Modified: 21 Nov 2024

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-36678

    Last Modified: 21 Nov 2024

    Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.

    Published: 26 Aug 2022
    8.1
    High

    CVE-2021-40285

    Last Modified: 21 Nov 2024

    htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.

    Published: 26 Aug 2022
    6.1
    Medium

    CVE-2021-39393

    Last Modified: 21 Nov 2024

    mm-wiki v0.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the markdown editor.

    Published: 26 Aug 2022
    7.5
    High

    CVE-2022-37151

    Last Modified: 21 Nov 2024

    There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0.

    Published: 26 Aug 2022
    9.8
    Critical

    CVE-2022-37152

    Last Modified: 21 Nov 2024

    An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"

    Published: 26 Aug 2022
    5.4
    Medium

    CVE-2022-37150

    Last Modified: 21 Nov 2024

    An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstname, address, middlename, lastname , gender, email, contact parameters.

    Published: 26 Aug 2022
    —
    Unknown

    CVE-2022-24304

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2564. Reason: This candidate is a duplicate of CVE-2022-2564. Notes: All CVE users should reference CVE-2022-2564 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Aug 2022
    6.1
    Medium

    CVE-2021-3427

    Last Modified: 21 Nov 2024

    The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

    Published: 26 Aug 2022
    3.3
    Low

    CVE-2021-3574

    Last Modified: 21 Nov 2024

    A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

    Published: 26 Aug 2022
    5.5
    Medium

    CVE-2022-2905

    Last Modified: 21 Nov 2024

    An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.

    Published: 26 Aug 2022
    7.5
    High

    CVE-2022-36537

    Last Modified: 3 Nov 2025

    ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

    Published: 26 Aug 2022
    2.7
    Low

    CVE-2022-36168

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:

    Published: 25 Aug 2022
    7.2
    High

    CVE-2022-36226

    Last Modified: 21 Nov 2024

    SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2021-3020

    Last Modified: 21 Nov 2024

    An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid program. This allows the hacluster user to invoke certain commands as root (with an attempt to limit this to safe combinations). This user is able to execute an interactive "shell" that isn't limited to the commands specified in hawk_invoke, allowing escalation to root.

    Published: 25 Aug 2022
    4.9
    Medium

    CVE-2021-32570

    Last Modified: 21 Nov 2024

    In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.

    Published: 25 Aug 2022
    7.5
    High

    CVE-2022-35192

    Last Modified: 21 Nov 2024

    D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.

    Published: 25 Aug 2022
    7.8
    High

    CVE-2022-30984

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the Rubrik Backup Service (RBS) Agent for Linux or Unix-based systems in Rubrik CDM 7.0.1, 7.0.1-p1, 7.0.1-p2 or 7.0.1-p3 before CDM 7.0.2-p2 could allow a local attacker to obtain root privileges by sending a crafted message to the RBS agent.

    Published: 25 Aug 2022
    8.1
    High

    CVE-2022-29850

    Last Modified: 21 Nov 2024

    Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.

    Published: 25 Aug 2022
    5.3
    Medium

    CVE-2022-36121

    Last Modified: 21 Nov 2024

    An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the UpdateOfflineHelpData administrative function. Abusing this function will allow any Blue Prism user to change the offline help URL to one of their choice, opening the possibility of spoofing the help page or executing a local file.

    Published: 25 Aug 2022
    8.1
    High

    CVE-2022-36120

    Last Modified: 21 Nov 2024

    An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a low/no privilege Blue Prism user account, the attacker can alter the server's settings by abusing the getChartData method, allowing the Blue Prism server to execute any MSSQL stored procedure by name.

    Published: 25 Aug 2022
    8.8
    High

    CVE-2022-36119

    Last Modified: 21 Nov 2024

    An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of insecure deserialization. Exploitation of this vulnerability allows for code to be executed in the context of the Blue Prism Server service.

    Published: 25 Aug 2022
    5.3
    Medium

    CVE-2022-36118

    Last Modified: 21 Nov 2024

    An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the SetProcessAttributes administrative function. Abusing this function will allow any Blue Prism user to publish, unpublish, or retire processes. Using this function, any logged-in user can change the status of a process, an action allowed only intended for users with the Edit Process permission.

    Published: 25 Aug 2022
    3.1
    Low

    CVE-2022-36117

    Last Modified: 21 Nov 2024

    An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for an administrative function. If credential access is configured to be accessible by a machine or the runtime resource security group, using further reverse engineering, an attacker can spoof a known machine and request known encrypted credentials to decrypt later.

    Published: 25 Aug 2022
    5.3
    Medium

    CVE-2022-36116

    Last Modified: 21 Nov 2024

    An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the setValidationInfo administrative function. Removing the validation applied to newly designed processes increases the chance of successfully hiding malicious code that could be executed in a production environment.

    Published: 25 Aug 2022
    7.1
    High

    CVE-2022-36115

    Last Modified: 21 Nov 2024

    An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for unintended functionality. An attacker can abuse the CreateProcessAutosave() method to inject their own functionality into a development process. If (upon a warning) a user decides to recover unsaved work by using the last saved version, the malicious code could enter the workflow. Should the process action stages not be fully reviewed before publishing, this could result in the malicious code being run in a production environment.

    Published: 25 Aug 2022