CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2022-29097

    Last Modified: 21 Nov 2024

    Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

    Published: 24 Jun 2022
    6.1
    Medium

    CVE-2022-29096

    Last Modified: 21 Nov 2024

    Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

    Published: 24 Jun 2022
    5.4
    Medium

    CVE-2022-33910

    Last Modified: 21 Nov 2024

    An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of downloading it as a file, causing the JavaScript code to execute.

    Published: 24 Jun 2022
    7.5
    High

    CVE-2022-22390

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.

    Published: 24 Jun 2022
    6.5
    Medium

    CVE-2022-22389

    Last Modified: 21 Nov 2024

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740.

    Published: 24 Jun 2022
    5.3
    Medium

    CVE-2022-29578

    Last Modified: 21 Nov 2024

    Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information such as name, address, and daily energy usage.

    Published: 24 Jun 2022
    5.9
    Medium

    CVE-2022-30028

    Last Modified: 21 Nov 2024

    Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2021-39409

    Last Modified: 21 Nov 2024

    A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without needing to be authenticated.

    Published: 24 Jun 2022
    6.1
    Medium

    CVE-2021-39408

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.php file

    Published: 24 Jun 2022
    5.3
    Medium

    CVE-2021-38879

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 209057.

    Published: 24 Jun 2022
    5.4
    Medium

    CVE-2021-38871

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208345.

    Published: 24 Jun 2022
    5.4
    Medium

    CVE-2021-29865

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 206091.

    Published: 24 Jun 2022
    3.3
    Low

    CVE-2021-20551

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 199149.

    Published: 24 Jun 2022
    4.3
    Medium

    CVE-2021-20544

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198931.

    Published: 24 Jun 2022
    5.4
    Medium

    CVE-2021-20543

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 198929.

    Published: 24 Jun 2022
    4.3
    Medium

    CVE-2021-20421

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

    Published: 24 Jun 2022
    5.3
    Medium

    CVE-2021-20355

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 194891.

    Published: 24 Jun 2022
    6.7
    Medium

    CVE-2021-42056

    Last Modified: 21 Nov 2024

    Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges.

    Published: 24 Jun 2022
    7.5
    High

    CVE-2021-40893

    Last Modified: 21 Nov 2024

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating crafted invalid emails.

    Published: 24 Jun 2022
    4.6
    Medium

    CVE-2022-33953

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-31767

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980.

    Published: 24 Jun 2022
    5.4
    Medium

    CVE-2022-22502

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124.

    Published: 24 Jun 2022
    6.1
    Medium

    CVE-2021-39047

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214349.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2021-38945

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.

    Published: 24 Jun 2022
    6.5
    Medium

    CVE-2021-29768

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.

    Published: 24 Jun 2022
    6.5
    Medium

    CVE-2022-20828

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER module as the root user. This vulnerability is due to improper handling of undefined command parameters. An attacker could exploit this vulnerability by using a crafted command on the CLI or by submitting a crafted HTTPS request to the web-based management interface of the Cisco ASA that is hosting the ASA FirePOWER module. Note: To exploit this vulnerability, the attacker must have administrative access to the Cisco ASA. A user who has administrative access to a particular Cisco ASA is also expected to have administrative access to the ASA FirePOWER module that is hosted by that Cisco ASA.

    Published: 24 Jun 2022
    9.1
    Critical

    CVE-2022-20829

    Last Modified: 21 Nov 2024

    A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to upload an ASDM image that contains malicious code to a device that is running Cisco ASA Software. This vulnerability is due to insufficient validation of the authenticity of an ASDM image during its installation on a device that is running Cisco ASA Software. An attacker could exploit this vulnerability by installing a crafted ASDM image on the device that is running Cisco ASA Software and then waiting for a targeted user to access that device using ASDM. A successful exploit could allow the attacker to execute arbitrary code on the machine of the targeted user with the privileges of that user on that machine. Notes: To successfully exploit this vulnerability, the attacker must have administrative privileges on the device that is running Cisco ASA Software. Potential targets are limited to users who manage the same device that is running Cisco ASA Software using ASDM. Cisco has released and will release software updates that address this vulnerability.

    Published: 24 Jun 2022
    4.9
    Medium

    CVE-2022-29330

    Last Modified: 21 Nov 2024

    Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.

    Published: 24 Jun 2022
    5.4
    Medium

    CVE-2022-27238

    Last Modified: 21 Nov 2024

    BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each time the attacker sends a private message to the victim or when notification about the attacker leaving room is displayed.

    Published: 24 Jun 2022
    7.8
    High

    CVE-2020-21046

    Last Modified: 4 Jul 2026

    A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as a SYSTEM privilege.

    Published: 24 Jun 2022
    9.4
    Critical

    CVE-2022-2102

    Last Modified: 16 Apr 2025

    Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-1668

    Last Modified: 16 Apr 2025

    Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.

    Published: 24 Jun 2022
    9.4
    Critical

    CVE-2022-2105

    Last Modified: 16 Apr 2025

    Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level meant only for the vendor. Web server root level access allows for changing of safety critical parameters.

    Published: 24 Jun 2022
    9.9
    Critical

    CVE-2022-2104

    Last Modified: 16 Apr 2025

    The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).

    Published: 24 Jun 2022
    7.5
    High

    CVE-2022-1667

    Last Modified: 16 Apr 2025

    Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script

    Published: 24 Jun 2022
    6.5
    Medium

    CVE-2022-1666

    Last Modified: 16 Apr 2025

    The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.

    Published: 24 Jun 2022
    9.8
    Critical

    CVE-2022-2103

    Last Modified: 16 Apr 2025

    An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.

    Published: 24 Jun 2022
    6.8
    Medium

    CVE-2022-1745

    Last Modified: 17 Apr 2025

    The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker with physical access may use this to gain administrative privileges on a device and install malicious code or perform arbitrary administrative actions.

    Published: 24 Jun 2022
    4.6
    Medium

    CVE-2022-1740

    Last Modified: 17 Apr 2025

    The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export, and application export functionality rely on self-attestation mechanisms. An attacker could leverage this vulnerability to disguise malicious applications on a device.

    Published: 24 Jun 2022
    6.8
    Medium

    CVE-2022-1742

    Last Modified: 17 Apr 2025

    The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an attacker to directly access the operating system. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.

    Published: 24 Jun 2022
    6.8
    Medium

    CVE-2022-1743

    Last Modified: 17 Apr 2025

    The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by specially crafted election definition files. An attacker could leverage this vulnerability to spread malicious code to ImageCast X devices from the EMS.

    Published: 24 Jun 2022
    6.8
    Medium

    CVE-2022-1741

    Last Modified: 17 Apr 2025

    The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or install malicious code.

    Published: 24 Jun 2022
    6.8
    Medium

    CVE-2022-1744

    Last Modified: 17 Apr 2025

    Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.

    Published: 24 Jun 2022
    4.6
    Medium

    CVE-2022-1747

    Last Modified: 17 Apr 2025

    The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker could leverage this vulnerability to print an arbitrary number of ballots without authorization.

    Published: 24 Jun 2022
    6.8
    Medium

    CVE-2022-1739

    Last Modified: 17 Apr 2025

    The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable against, a cryptographic key provided by the manufacturer to detect tampering. An attacker could leverage this vulnerability to install malicious code, which could also be spread to other vulnerable ImageCast X devices via removable media.

    Published: 24 Jun 2022
    7.6
    High

    CVE-2022-1746

    Last Modified: 17 Apr 2025

    The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive information and perform privileged actions, potentially affecting other election equipment.

    Published: 24 Jun 2022
    7.5
    High

    CVE-2022-2119

    Last Modified: 3 Nov 2025

    OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

    Published: 24 Jun 2022
    7.5
    High

    CVE-2022-2121

    Last Modified: 3 Nov 2025

    OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.

    Published: 24 Jun 2022
    7.5
    High

    CVE-2022-2120

    Last Modified: 3 Nov 2025

    OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

    Published: 24 Jun 2022
    6.5
    Medium

    CVE-2013-1891

    Last Modified: 21 Nov 2024

    In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.

    Published: 24 Jun 2022