CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-35410

    Last Modified: 21 Nov 2024

    mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.

    Published: 8 Jul 2022
    5.4
    Medium

    CVE-2022-34306

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229435.

    Published: 8 Jul 2022
    5.4
    Medium

    CVE-2022-34167

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229432.

    Published: 8 Jul 2022
    5.4
    Medium

    CVE-2022-34166

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229430.

    Published: 8 Jul 2022
    5.4
    Medium

    CVE-2022-34160

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 229330.

    Published: 8 Jul 2022
    4.3
    Medium

    CVE-2022-35406

    Last Modified: 21 Nov 2024

    A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

    Published: 8 Jul 2022
    9.8
    Critical

    CVE-2022-28623

    Last Modified: 21 Nov 2024

    Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd library Patch 9 for HP-UX.

    Published: 8 Jul 2022
    4.8
    Medium

    CVE-2022-28624

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE FlexFabric 5945_7.10.R6635.

    Published: 8 Jul 2022
    8.8
    High

    CVE-2022-33011

    Last Modified: 21 Nov 2024

    Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack.

    Published: 8 Jul 2022
    6.1
    Medium

    CVE-2022-32115

    Last Modified: 21 Nov 2024

    An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.

    Published: 8 Jul 2022
    5.4
    Medium

    CVE-2022-31290

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.

    Published: 8 Jul 2022
    4.3
    Medium

    CVE-2022-30852

    Last Modified: 21 Nov 2024

    Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).

    Published: 8 Jul 2022
    6.7
    Medium

    CVE-2021-33655

    Last Modified: 21 Nov 2024

    When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

    Published: 8 Jul 2022
    10
    Critical

    CVE-2021-41037

    Last Modified: 21 Nov 2024

    In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings that usually require particular attention in term of security. Although p2 has built-in strategies to ensure artifacts are signed and then to help establish trust, there is no such strategy for the metadata part that does configure such touchpoints. As a result, it's possible to install a unit that will run malicious code during installation without user receiving any warning about this installation step being risky when coming from untrusted source.

    Published: 8 Jul 2022
    5.5
    Medium

    CVE-2022-3821

    Last Modified: 2 May 2025

    An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2022-2348

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jul 2022
    —
    Unknown

    CVE-2022-2349

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jul 2022
    6.5
    Medium

    CVE-2022-32215

    Last Modified: 30 Apr 2025

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).

    Published: 8 Jul 2022
    5.3
    Medium

    CVE-2022-32222

    Last Modified: 30 Apr 2025

    A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

    Published: 8 Jul 2022
    7.7
    High

    CVE-2022-31627

    Last Modified: 21 Nov 2024

    In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

    Published: 8 Jul 2022
    6.6
    Medium

    CVE-2022-2447

    Last Modified: 21 Nov 2024

    A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

    Published: 8 Jul 2022
    10
    Critical

    CVE-2022-31137

    Last Modified: 22 Apr 2025

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 8 Jul 2022
    6.5
    Medium

    CVE-2022-32213

    Last Modified: 30 Apr 2025

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).

    Published: 8 Jul 2022
    6.5
    Medium

    CVE-2022-32214

    Last Modified: 30 Apr 2025

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

    Published: 8 Jul 2022
    8.1
    High

    CVE-2022-32212

    Last Modified: 30 Apr 2025

    A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.

    Published: 8 Jul 2022
    4.8
    Medium

    CVE-2022-32061

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.

    Published: 7 Jul 2022
    8
    High

    CVE-2022-33936

    Last Modified: 21 Nov 2024

    Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a critical issue; so Dell recommends customers to upgrade at the earliest opportunity.

    Published: 7 Jul 2022
    7.8
    High

    CVE-2022-32481

    Last Modified: 21 Nov 2024

    Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appliance deployments. A lower-privileged authenticated user can chain docker commands to escalate privileges to root leading to complete system takeover.

    Published: 7 Jul 2022
    5.9
    Medium

    CVE-2022-31029

    Last Modified: 23 Apr 2025

    AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XSS")</script>` in the field marked with "Domain to look for" and hitting <kbd>enter</kbd> (or clicking on any of the buttons) will execute the script. The user must be logged in to use this vulnerability. Usually only administrators have login access to pi-hole, minimizing the risks. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 7 Jul 2022
    5.3
    Medium

    CVE-2021-41042

    Last Modified: 21 Nov 2024

    In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an external DTD to be retrieved.

    Published: 7 Jul 2022
    8.3
    High

    CVE-2022-33680

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-27732

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-27731

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19158

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19155

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19154

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19153

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2019-19152

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 7 Jul 2022
    9.8
    Critical

    CVE-2021-29281

    Last Modified: 21 Nov 2024

    File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-25591

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-25590

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-25589

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-25588

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-25587

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-25586

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    —
    Unknown

    CVE-2020-25585

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 7 Jul 2022
    9.8
    Critical

    CVE-2021-35283

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.

    Published: 7 Jul 2022