CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2017-20117

    Last Modified: 15 Apr 2025

    A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022
    3.5
    Low

    CVE-2017-20116

    Last Modified: 15 Apr 2025

    A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the argument checked_group_id leads to basic cross site scripting (Reflected). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022
    3.5
    Low

    CVE-2017-20115

    Last Modified: 15 Apr 2025

    A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown processing of the file /admin/conferences/list/. The manipulation of the argument sort leads to basic cross site scripting (Reflected). The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022
    3.5
    Low

    CVE-2017-20114

    Last Modified: 15 Apr 2025

    A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022
    3.5
    Low

    CVE-2017-20113

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2022
    6.1
    Medium

    CVE-2021-39074

    Last Modified: 21 Nov 2024

    IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 29 Jun 2022
    6.1
    Medium

    CVE-2022-2252

    Last Modified: 21 Nov 2024

    Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

    Published: 29 Jun 2022
    5.9
    Medium

    CVE-2022-32969

    Last Modified: 21 Nov 2024

    MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue.

    Published: 29 Jun 2022
    6.1
    Medium

    CVE-2020-26877

    Last Modified: 21 Nov 2024

    ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI submitted with the authorization request, without checking whether the redirect URI is registered by the client who initiated the request. This allows an attacker to craft a request with a manipulated redirect URI (redirect_uri parameter), which is under the attacker's control, and consequently obtain the leaked authorization code when the server redirects the client to the manipulated redirect URI with an authorization code. NOTE: this is similar to CVE-2019-3778.

    Published: 29 Jun 2022
    7.8
    High

    CVE-2022-33037

    Last Modified: 21 Nov 2024

    A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.

    Published: 29 Jun 2022
    7.3
    High

    CVE-2022-34043

    Last Modified: 21 Nov 2024

    Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack and execute arbitrary code.

    Published: 29 Jun 2022
    7.8
    High

    CVE-2022-33036

    Last Modified: 21 Nov 2024

    A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.

    Published: 29 Jun 2022
    7.8
    High

    CVE-2022-33035

    Last Modified: 21 Nov 2024

    XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

    Published: 29 Jun 2022
    7.5
    High

    CVE-2022-33023

    Last Modified: 21 Nov 2024

    CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.

    Published: 29 Jun 2022
    7.5
    High

    CVE-2022-33021

    Last Modified: 21 Nov 2024

    CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30.

    Published: 29 Jun 2022
    9.8
    Critical

    CVE-2022-33107

    Last Modified: 21 Nov 2024

    ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

    Published: 29 Jun 2022
    4.3
    Medium

    CVE-2021-40642

    Last Modified: 21 Nov 2024

    Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

    Published: 29 Jun 2022
    7.8
    High

    CVE-2017-20112

    Last Modified: 15 Apr 2025

    A vulnerability has been found in IVPN Client 2.6.6120.33863 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument --up cmd leads to improper privilege management. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.6.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 29 Jun 2022
    7.3
    High

    CVE-2017-20111

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in Teleopti WFM 7.1.0. This affects an unknown part of the component Administration. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 29 Jun 2022
    4.3
    Medium

    CVE-2017-20110

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionality of the component Administration. The manipulation as part of JSON leads to information disclosure (Credentials). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 29 Jun 2022
    4.3
    Medium

    CVE-2017-20109

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the file /TeleoptiWFM/Administration/GetOneTenant of the component Administration. The manipulation leads to information disclosure (Credentials). The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 29 Jun 2022
    3.5
    Low

    CVE-2017-20108

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the file /wordpress/wp-admin/options-general.php. The manipulation with the input "><script>alert(1)</script> leads to basic cross site scripting. It is possible to initiate the attack remotely.

    Published: 29 Jun 2022
    6.1
    Medium

    CVE-2022-29272

    Last Modified: 21 Nov 2024

    In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

    Published: 29 Jun 2022
    6.5
    Medium

    CVE-2022-29271

    Last Modified: 21 Nov 2024

    In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.

    Published: 29 Jun 2022
    4.3
    Medium

    CVE-2022-29270

    Last Modified: 21 Nov 2024

    In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.

    Published: 29 Jun 2022
    6.5
    Medium

    CVE-2022-29269

    Last Modified: 21 Nov 2024

    In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.

    Published: 29 Jun 2022
    5.4
    Medium

    CVE-2022-28803

    Last Modified: 21 Nov 2024

    In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR).

    Published: 29 Jun 2022
    4.3
    Medium

    CVE-2022-31266

    Last Modified: 20 Mar 2025

    In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.

    Published: 29 Jun 2022
    6.1
    Medium

    CVE-2022-31897

    Last Modified: 21 Nov 2024

    SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.

    Published: 29 Jun 2022
    5.5
    Medium

    CVE-2022-2318

    Last Modified: 21 Nov 2024

    There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.

    Published: 29 Jun 2022
    4.8
    Medium

    CVE-2022-3260

    Last Modified: 23 Apr 2025

    The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.

    Published: 29 Jun 2022
    8.3
    High

    CVE-2022-33639

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 29 Jun 2022
    5.4
    Medium

    CVE-2022-25238

    Last Modified: 21 Nov 2024

    Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website content via XHR by an authenticated CMS user if the cwp-core module is not installed on the sanitise_server_side contig is not set to true in project code.

    Published: 28 Jun 2022
    4.3
    Medium

    CVE-2022-29858

    Last Modified: 21 Nov 2024

    Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.

    Published: 28 Jun 2022
    6.5
    Medium

    CVE-2022-24444

    Last Modified: 21 Nov 2024

    Silverstripe silverstripe/framework through 4.10 allows Session Fixation.

    Published: 28 Jun 2022
    6.5
    Medium

    CVE-2021-41559

    Last Modified: 21 Nov 2024

    Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.

    Published: 28 Jun 2022
    6.1
    Medium

    CVE-2020-19897

    Last Modified: 5 May 2025

    A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.

    Published: 28 Jun 2022
    9.8
    Critical

    CVE-2020-19896

    Last Modified: 21 Nov 2024

    File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.

    Published: 28 Jun 2022
    9.8
    Critical

    CVE-2022-31887

    Last Modified: 21 Nov 2024

    Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.

    Published: 28 Jun 2022
    6.5
    Medium

    CVE-2022-31884

    Last Modified: 21 Nov 2024

    Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.

    Published: 28 Jun 2022
    8.8
    High

    CVE-2022-31883

    Last Modified: 21 Nov 2024

    Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.

    Published: 28 Jun 2022
    6.5
    Medium

    CVE-2022-31886

    Last Modified: 21 Nov 2024

    Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.

    Published: 28 Jun 2022
    9.8
    Critical

    CVE-2022-31885

    Last Modified: 21 Nov 2024

    Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.

    Published: 28 Jun 2022
    4
    Medium

    CVE-2021-3435

    Last Modified: 21 Nov 2024

    Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh

    Published: 28 Jun 2022
    4.9
    Medium

    CVE-2021-3434

    Last Modified: 21 Nov 2024

    Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w87-6rfp-cfrm

    Published: 28 Jun 2022
    4
    Medium

    CVE-2021-3433

    Last Modified: 21 Nov 2024

    Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptional Conditions (CWE-703). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3c2f-w4v6-qxrp

    Published: 28 Jun 2022
    4.3
    Medium

    CVE-2021-3432

    Last Modified: 21 Nov 2024

    Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7364-p4wc-8mj4

    Published: 28 Jun 2022
    4.3
    Medium

    CVE-2021-3431

    Last Modified: 21 Nov 2024

    Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7548-5m6f-mqv9

    Published: 28 Jun 2022
    6.5
    Medium

    CVE-2021-3430

    Last Modified: 21 Nov 2024

    Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr

    Published: 28 Jun 2022
    —
    Unknown

    CVE-2022-2246

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Jun 2022