CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-22485

    Last Modified: 21 Nov 2024

    In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.

    Published: 17 Jun 2022
    6.1
    Medium

    CVE-2022-32444

    Last Modified: 21 Nov 2024

    An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2021-40903

    Last Modified: 21 Nov 2024

    A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

    Published: 17 Jun 2022
    5.5
    Medium

    CVE-2022-31246

    Last Modified: 21 Nov 2024

    paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR code data). On Windows, this can lead to capture of credentials over SMB. On Linux and UNIX, it can lead to a denial of service by specifying the /dev/zero filename.

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2022-31355

    Last Modified: 21 Nov 2024

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2022-31356

    Last Modified: 21 Nov 2024

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2022-31357

    Last Modified: 21 Nov 2024

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.

    Published: 17 Jun 2022
    8.8
    High

    CVE-2020-36549

    Last Modified: 16 Apr 2025

    A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating system. Missing patches might introduce an excessive attack surface. Access to the local network is required for this attack to succeed.

    Published: 17 Jun 2022
    5.9
    Medium

    CVE-2020-36548

    Last Modified: 16 Apr 2025

    A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibilities. It is possible to launch the attack on the local host.

    Published: 17 Jun 2022
    5.9
    Medium

    CVE-2020-36547

    Last Modified: 16 Apr 2025

    A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change the configuration settings.

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2022-31296

    Last Modified: 21 Nov 2024

    Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.

    Published: 17 Jun 2022
    8.8
    High

    CVE-2019-12352

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.

    Published: 17 Jun 2022
    7.2
    High

    CVE-2019-12353

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.

    Published: 17 Jun 2022
    7.2
    High

    CVE-2019-12354

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.

    Published: 17 Jun 2022
    8.8
    High

    CVE-2019-12355

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.

    Published: 17 Jun 2022
    8.8
    High

    CVE-2019-12356

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.

    Published: 17 Jun 2022
    7.2
    High

    CVE-2019-12357

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.

    Published: 17 Jun 2022
    8.8
    High

    CVE-2019-12358

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.

    Published: 17 Jun 2022
    7.2
    High

    CVE-2019-12359

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.

    Published: 17 Jun 2022
    6.1
    Medium

    CVE-2021-45026

    Last Modified: 21 Nov 2024

    ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

    Published: 17 Jun 2022
    7.5
    High

    CVE-2021-45025

    Last Modified: 21 Nov 2024

    ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2021-45024

    Last Modified: 21 Nov 2024

    ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2022-31784

    Last Modified: 21 Nov 2024

    A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A successful exploit could allow arbitrary code execution.

    Published: 17 Jun 2022
    7.5
    High

    CVE-2022-32276

    Last Modified: 21 Nov 2024

    Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability

    Published: 17 Jun 2022
    7.5
    High

    CVE-2021-41490

    Last Modified: 21 Nov 2024

    Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.

    Published: 17 Jun 2022
    5.4
    Medium

    CVE-2022-2113

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.

    Published: 17 Jun 2022
    8.8
    High

    CVE-2022-2112

    Last Modified: 21 Nov 2024

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

    Published: 17 Jun 2022
    8.8
    High

    CVE-2022-2111

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

    Published: 17 Jun 2022
    9.8
    Critical

    CVE-2021-41408

    Last Modified: 21 Nov 2024

    VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.

    Published: 17 Jun 2022
    7
    High

    CVE-2022-33915

    Last Modified: 21 Nov 2024

    Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch package is not a replacement for updating to a log4j version that mitigates CVE-2021-44228 or CVE-2021-45046; it provides a temporary mitigation to CVE-2021-44228 by hotpatching the local Java virtual machines. To do so, it iterates through all running Java processes, performs several checks, and executes the Java virtual machine with the same permissions and capabilities as the running process to load the hotpatch. A local user could cause the hotpatch script to execute a binary with elevated privileges by running a custom java process that performs exec() of an SUID binary after the hotpatch has observed the process path and before it has observed its effective user ID.

    Published: 17 Jun 2022
    7.8
    High

    CVE-2022-33912

    Last Modified: 21 Nov 2024

    A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts located at /var/lib/dpkg/info/ will be owned by the user and the group with ID 1001. If such a user exists on the system, they can change the content of these files (which are then executed by root). This leads to a local privilege escalation on the monitored host. Version 1.6 through 1.6.9p29, version 2.0 through 2.0.0p26, version 2.1 through 2.1.0p3, and version 2.2.0i1 are affected.

    Published: 17 Jun 2022
    6.3
    Medium

    CVE-2018-25044

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processing of the component Guest Account. The manipulation leads to privilege escalation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 17 Jun 2022
    5
    Medium

    CVE-2018-25043

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 17 Jun 2022
    5
    Medium

    CVE-2018-25042

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.

    Published: 17 Jun 2022
    6.3
    Medium

    CVE-2018-25041

    Last Modified: 15 Apr 2025

    A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionality of the component JSON RPC Server. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 17 Jun 2022
    6.3
    Medium

    CVE-2018-25040

    Last Modified: 15 Apr 2025

    A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component HTTP RPC Server. The manipulation leads to privilege escalation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 17 Jun 2022
    —
    Unknown

    CVE-2022-33933

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 17 Jun 2022
    6.5
    Medium

    CVE-2022-30327

    Last Modified: 21 Nov 2024

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the pre-shared key of the Wi-Fi router if the interface's IP address is known.

    Published: 16 Jun 2022
    6.5
    Medium

    CVE-2022-30328

    Last Modified: 21 Nov 2024

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and password of the interface.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-30329

    Last Modified: 21 Nov 2024

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2022-30326

    Last Modified: 21 Nov 2024

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The network pre-shared key field on the web interface is vulnerable to XSS. An attacker can use a simple XSS payload to crash the basic.config page of the web interface.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2022-30325

    Last Modified: 21 Nov 2024

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for both 2.4 GHz and 5 GHz networks can be guessed or brute-forced by an attacker within range of the Wi-Fi network.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2022-26173

    Last Modified: 21 Nov 2024

    JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2018-18907

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-33739

    Last Modified: 21 Nov 2024

    CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could allow a remote attacker to potentially view the contents of any file on the system.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-33756

    Last Modified: 21 Nov 2024

    CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data.

    Published: 16 Jun 2022
    5.3
    Medium

    CVE-2022-33755

    Last Modified: 21 Nov 2024

    CA Automic Automation 12.2 and 12.3 contain an insecure input handling vulnerability in the Automic Agent that could allow a remote attacker to potentially enumerate users.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-33754

    Last Modified: 21 Nov 2024

    CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

    Published: 16 Jun 2022
    6.1
    Medium

    CVE-2022-31299

    Last Modified: 21 Nov 2024

    Haraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2022-33753

    Last Modified: 21 Nov 2024

    CA Automic Automation 12.2 and 12.3 contain an insecure file creation and handling vulnerability in the Automic agent that could allow a user to potentially elevate privileges.

    Published: 16 Jun 2022