CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2022-31112

    Last Modified: 23 Apr 2025

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryController now removes protected fields from the client response. Users are advised to upgrade. Users unable t upgrade should use `Parse.Cloud.afterLiveQueryEvent` to manually remove protected fields.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-22496

    Last Modified: 21 Nov 2024

    While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942.

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2022-22487

    Last Modified: 21 Nov 2024

    An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.

    Published: 30 Jun 2022
    5.5
    Medium

    CVE-2022-22478

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.

    Published: 30 Jun 2022
    7.5
    High

    CVE-2022-22474

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operations on TCP/IP sockets. This can result in a denial of service for IBM Spectrum Protect client operations. IBM X-Force ID: 225348.

    Published: 30 Jun 2022
    4.9
    Medium

    CVE-2021-37791

    Last Modified: 21 Nov 2024

    MyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?userCode=admin.

    Published: 30 Jun 2022
    —
    Unknown

    CVE-2013-4309

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2021-37778

    Last Modified: 21 Nov 2024

    There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution.

    Published: 30 Jun 2022
    7.2
    High

    CVE-2021-37770

    Last Modified: 21 Nov 2024

    Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Htaccess file and write it to AddType application / x-httpd-php.jpg. In this way, an attacker can upload a picture with shell, treat it as PHP, execute commands, so as to take down website resources.

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2021-41506

    Last Modified: 21 Nov 2024

    Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.

    Published: 30 Jun 2022
    —
    Unknown

    CVE-2013-4146

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3414. Reason: This candidate is a duplicate of CVE-2012-3414. Notes: All CVE users should reference CVE-2012-3414 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-33043

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers to execute arbitrary web scripts or HTML via a crafted excel file.

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2021-40663

    Last Modified: 21 Nov 2024

    deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2021-40643

    Last Modified: 21 Nov 2024

    EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by default/usr/sbin/sendmail) it is possible to execute any command, which will be executed when we make a test of the configuration ("send test mail").

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-26135

    Last Modified: 21 Nov 2024

    A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

    Published: 30 Jun 2022
    6.3
    Medium

    CVE-2017-20125

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2022
    6.3
    Medium

    CVE-2017-20124

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2022
    8.8
    High

    CVE-2017-20123

    Last Modified: 15 Apr 2025

    A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 30 Jun 2022
    3.5
    Low

    CVE-2017-20122

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2022
    7.8
    High

    CVE-2017-20121

    Last Modified: 15 Apr 2025

    A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Database Management. The manipulation leads to improper privilege management. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2022
    5.5
    Medium

    CVE-2022-2057

    Last Modified: 21 Nov 2024

    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

    Published: 30 Jun 2022
    5.5
    Medium

    CVE-2022-2058

    Last Modified: 21 Nov 2024

    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34903

    Last Modified: 21 Nov 2024

    GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

    Published: 30 Jun 2022
    4.6
    Medium

    CVE-2022-1955

    Last Modified: 21 Nov 2024

    Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

    Published: 30 Jun 2022
    5.5
    Medium

    CVE-2022-2056

    Last Modified: 21 Nov 2024

    Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

    Published: 30 Jun 2022
    7.8
    High

    CVE-2022-2257

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

    Published: 30 Jun 2022
    7.4
    High

    CVE-2022-3259

    Last Modified: 22 Apr 2025

    Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

    Published: 30 Jun 2022
    7.5
    High

    CVE-2022-33082

    Last Modified: 21 Nov 2024

    An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2022-34835

    Last Modified: 12 May 2026

    In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.

    Published: 29 Jun 2022
    9.8
    Critical

    CVE-2021-40597

    Last Modified: 21 Nov 2024

    The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

    Published: 29 Jun 2022
    6.8
    Medium

    CVE-2022-30467

    Last Modified: 21 Nov 2024

    Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF.

    Published: 29 Jun 2022
    —
    Unknown

    CVE-2013-4126

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Jun 2022
    —
    Unknown

    CVE-2013-2252

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA

    Published: 29 Jun 2022
    —
    Unknown

    CVE-2013-2235

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-2073

    Last Modified: 21 Nov 2024

    Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

    Published: 29 Jun 2022
    5.3
    Medium

    CVE-2022-31110

    Last Modified: 22 Apr 2025

    RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout` parameters can cause an abnormally high CPU. This results in an impact on the performance of the servers and RSSHub services which may lead to a denial of service. This issue has been fixed in commit 5c4177441417 and all users are advised to upgrade. There are no known workarounds for this issue.

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-31058

    Last Modified: 23 Apr 2025

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the capability to create a new tracker can execute arbitrary SQL queries. Users are advised to upgrade. There is no known workaround for this issue.

    Published: 29 Jun 2022
    6.5
    Medium

    CVE-2022-31063

    Last Modified: 23 Apr 2025

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.111 the title of a document is not properly escaped in the search result of MyDocmanSearch widget and in the administration page of the locked documents. A malicious user with the capability to create a document could force victim to execute uncontrolled code. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 29 Jun 2022
    4.3
    Medium

    CVE-2022-31032

    Last Modified: 23 Apr 2025

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.58 authorizations are not properly verified when creating projects or trackers from projects marked as templates. Users can get access to information in those template projects because the permissions model is not properly enforced. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-33060

    Last Modified: 21 Nov 2024

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-33061

    Last Modified: 21 Nov 2024

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.

    Published: 29 Jun 2022
    8.3
    High

    CVE-2022-33638

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 29 Jun 2022
    8.3
    High

    CVE-2022-30192

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-33059

    Last Modified: 21 Nov 2024

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_train.

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-33058

    Last Modified: 21 Nov 2024

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_message.

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-33057

    Last Modified: 21 Nov 2024

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.

    Published: 29 Jun 2022
    7.2
    High

    CVE-2022-33042

    Last Modified: 21 Nov 2024

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php.

    Published: 29 Jun 2022
    4.3
    Medium

    CVE-2017-20120

    Last Modified: 20 Aug 2026

    A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022
    3.5
    Low

    CVE-2017-20119

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022
    3.5
    Low

    CVE-2017-20118

    Last Modified: 15 Apr 2025

    A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripting (DOM). The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022