CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2022-32400

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32399

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32398

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32397

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32396

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32395

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32394

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32393

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32392

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4

    Published: 24 Jun 2022
    8.8
    High

    CVE-2022-32391

    Last Modified: 21 Nov 2024

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

    Published: 24 Jun 2022
    6.1
    Medium

    CVE-2022-32209

    Last Modified: 3 Nov 2025

    # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags to allow both `select` and `style` elements.Code is only impacted if allowed tags are being overridden. This may be done via application configuration:```ruby# In config/application.rbconfig.action_view.sanitized_allowed_tags = ["select", "style"]```see https://guides.rubyonrails.org/configuring.html#configuring-action-viewOr it may be done with a `:tags` option to the Action View helper `sanitize`:```<%= sanitize @comment.body, tags: ["select", "style"] %>```see https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-sanitizeOr it may be done with Rails::Html::SafeListSanitizer directly:```ruby# class-level optionRails::Html::SafeListSanitizer.allowed_tags = ["select", "style"]```or```ruby# instance-level optionRails::Html::SafeListSanitizer.new.sanitize(@article.body, tags: ["select", "style"])```All users overriding the allowed tags by any of the above mechanisms to include both "select" and "style" should either upgrade or use one of the workarounds immediately.## ReleasesThe FIXED releases are available at the normal locations.## WorkaroundsRemove either `select` or `style` from the overridden allowed tags.## CreditsThis vulnerability was responsibly reported by [windshock](https://hackerone.com/windshock?type=user).

    Published: 24 Jun 2022
    6.5
    Medium

    CVE-2022-2147

    Last Modified: 21 Nov 2024

    Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.

    Published: 23 Jun 2022
    4.8
    Medium

    CVE-2022-32987

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.

    Published: 23 Jun 2022
    6.3
    Medium

    CVE-2022-26864

    Last Modified: 21 Nov 2024

    Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

    Published: 23 Jun 2022
    6.3
    Medium

    CVE-2022-26863

    Last Modified: 21 Nov 2024

    Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

    Published: 23 Jun 2022
    6.3
    Medium

    CVE-2022-26862

    Last Modified: 21 Nov 2024

    Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls in SMM.

    Published: 23 Jun 2022
    5.4
    Medium

    CVE-2021-46824

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.

    Published: 23 Jun 2022
    6.1
    Medium

    CVE-2021-29055

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.

    Published: 23 Jun 2022
    4.3
    Medium

    CVE-2022-34013

    Last Modified: 21 Nov 2024

    OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.

    Published: 23 Jun 2022
    4.3
    Medium

    CVE-2022-34011

    Last Modified: 21 Nov 2024

    OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.

    Published: 23 Jun 2022
    6.5
    Medium

    CVE-2022-34012

    Last Modified: 21 Nov 2024

    Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.

    Published: 23 Jun 2022
    7.2
    High

    CVE-2022-33114

    Last Modified: 21 Nov 2024

    Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.

    Published: 23 Jun 2022
    5.4
    Medium

    CVE-2022-33113

    Last Modified: 21 Nov 2024

    Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.

    Published: 23 Jun 2022
    7.5
    High

    CVE-2021-40956

    Last Modified: 21 Nov 2024

    LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

    Published: 23 Jun 2022
    7.2
    High

    CVE-2021-40955

    Last Modified: 21 Nov 2024

    SQL injection exists in LaiKetui v3.5.0 the background administrator list.

    Published: 23 Jun 2022
    9.8
    Critical

    CVE-2021-40954

    Last Modified: 21 Nov 2024

    Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

    Published: 23 Jun 2022
    5.7
    Medium

    CVE-2022-31009

    Last Modified: 23 Apr 2025

    wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when converting an integer value into the corresponding enum value, causing an exception instead of a fallback to a default value. This issue is fixed in [wire-ios](https://github.com/wireapp/wire-ios/commit/caa0e27dbe51f9edfda8c7a9f017d93b8cfddefb) and in Wire for iOS 3.100. There is no workaround available, but users may use other Wire clients (such as the [web app](https://app.wire.com)) to continue using Wire, or upgrade their client.

    Published: 23 Jun 2022
    4.3
    Medium

    CVE-2017-20091

    Last Modified: 15 Apr 2025

    A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.

    Published: 23 Jun 2022
    4.3
    Medium

    CVE-2017-20090

    Last Modified: 15 Apr 2025

    A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.

    Published: 23 Jun 2022
    3.5
    Low

    CVE-2017-20089

    Last Modified: 15 Apr 2025

    A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely.

    Published: 23 Jun 2022
    4.3
    Medium

    CVE-2017-20088

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.

    Published: 23 Jun 2022
    3.5
    Low

    CVE-2017-20087

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.

    Published: 23 Jun 2022
    6.3
    Medium

    CVE-2017-20086

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.

    Published: 23 Jun 2022
    3.5
    Low

    CVE-2017-20085

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

    Published: 23 Jun 2022
    6.1
    Medium

    CVE-2022-34305

    Last Modified: 21 Nov 2024

    In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.

    Published: 23 Jun 2022
    —
    Unknown

    CVE-2022-34395

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 23 Jun 2022
    —
    Unknown

    CVE-2022-34461

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 23 Jun 2022
    6.5
    Medium

    CVE-2021-46784

    Last Modified: 21 Nov 2024

    In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

    Published: 23 Jun 2022
    7.8
    High

    CVE-2022-2182

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 23 Jun 2022
    3.5
    Low

    CVE-2022-3563

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer dereference. It is recommended to apply a patch to fix this issue. VDB-211086 is the identifier assigned to this vulnerability.

    Published: 23 Jun 2022
    7.8
    High

    CVE-2022-2175

    Last Modified: 21 Nov 2024

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

    Published: 23 Jun 2022
    7.8
    High

    CVE-2022-2183

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

    Published: 23 Jun 2022
    5.5
    Medium

    CVE-2022-33124

    Last Modified: 21 Nov 2024

    AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application

    Published: 22 Jun 2022
    9.8
    Critical

    CVE-2022-33127

    Last Modified: 21 Nov 2024

    The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.

    Published: 22 Jun 2022
    6.1
    Medium

    CVE-2022-34328

    Last Modified: 21 Nov 2024

    PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.

    Published: 22 Jun 2022
    7.5
    High

    CVE-2022-33097

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.

    Published: 22 Jun 2022
    7.5
    High

    CVE-2022-33096

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.

    Published: 22 Jun 2022
    7.5
    High

    CVE-2022-33095

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

    Published: 22 Jun 2022
    7.5
    High

    CVE-2022-33094

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.

    Published: 22 Jun 2022
    7.5
    High

    CVE-2022-33092

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.

    Published: 22 Jun 2022