CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-33752

    Last Modified: 21 Nov 2024

    CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-33751

    Last Modified: 21 Nov 2024

    CA Automic Automation 12.2 and 12.3 contain an insecure memory handling vulnerability in the Automic agent that could allow a remote attacker to potentially access sensitive data.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-33750

    Last Modified: 21 Nov 2024

    CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2020-25459

    Last Modified: 21 Nov 2024

    An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitive information during the training process of machine learning joint modeling.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2021-36608

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.

    Published: 16 Jun 2022
    8.1
    High

    CVE-2021-46820

    Last Modified: 21 Nov 2024

    Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php

    Published: 16 Jun 2022
    8.1
    High

    CVE-2021-37764

    Last Modified: 21 Nov 2024

    Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2021-36609

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2020-28865

    Last Modified: 21 Nov 2024

    An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2021-33295

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-31295

    Last Modified: 22 Apr 2025

    An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.

    Published: 16 Jun 2022
    5.3
    Medium

    CVE-2022-27512

    Last Modified: 21 Nov 2024

    Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.

    Published: 16 Jun 2022
    8.1
    High

    CVE-2022-27511

    Last Modified: 21 Nov 2024

    Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-24562

    Last Modified: 4 Jul 2026

    In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2020-35597

    Last Modified: 21 Nov 2024

    Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-31464

    Last Modified: 21 Nov 2024

    Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.

    Published: 16 Jun 2022
    6.5
    Medium

    CVE-2022-31294

    Last Modified: 22 Apr 2025

    An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-29866

    Last Modified: 21 Nov 2024

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2021-41487

    Last Modified: 21 Nov 2024

    NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2022-31301

    Last Modified: 21 Nov 2024

    Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.

    Published: 16 Jun 2022
    4.8
    Medium

    CVE-2021-36827

    Last Modified: 21 Nov 2024

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-29863

    Last Modified: 21 Nov 2024

    OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30664

    Last Modified: 23 Apr 2025

    Adobe Animate version 22.0.5 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30657

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30656

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30655

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30654

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-29864

    Last Modified: 21 Nov 2024

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30653

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30652

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30651

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30650

    Last Modified: 23 Apr 2025

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30665

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-29862

    Last Modified: 21 Nov 2024

    An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30663

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30662

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30661

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30660

    Last Modified: 21 Nov 2024

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30659

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    7.8
    High

    CVE-2022-30658

    Last Modified: 23 Apr 2025

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Jun 2022
    8.8
    High

    CVE-2022-30670

    Last Modified: 21 Nov 2024

    RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploitation of this issue does not require user interaction.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2022-31298

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability in the ads comment section of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

    Published: 16 Jun 2022
    4.8
    Medium

    CVE-2021-41421

    Last Modified: 21 Nov 2024

    A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-29865

    Last Modified: 21 Nov 2024

    OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-31382

    Last Modified: 21 Nov 2024

    Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

    Published: 16 Jun 2022
    5.4
    Medium

    CVE-2021-41420

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-31383

    Last Modified: 21 Nov 2024

    Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

    Published: 16 Jun 2022
    7.5
    High

    CVE-2022-1642

    Last Modified: 21 Nov 2024

    A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the Swift standard library, the Codable protocol; and the JSONDecoder class offered by swift-corelibs-foundation, which can deserialize types that adopt the Codable protocol based on the content of a provided JSON document. When a type that adopts Codable requests the initialization of a field with an integer value, the JSONDecoder class uses a type-erased container with different accessor methods to attempt and coerce a corresponding JSON value and produce an integer. In the case the JSON value was a numeric literal with a floating-point portion, JSONDecoder used different type-eraser methods during validation than it did during the final casting of the value. The checked casting produces a deterministic crash due to this mismatch. The JSONDecoder class is often wrapped by popular Swift-based web frameworks to parse the body of HTTP requests and perform basic type validation. This makes the attack low-effort: sending a specifically crafted JSON document during a request to these endpoints will cause them to crash. The attack does not have any confidentiality or integrity risks in and of itself; the crash is produced deterministically by an abort function that ensures that execution does not continue in the face of this violation of assumptions. However, unexpected crashes can lead to violations of invariants in services, so it's possible that this attack can be used to trigger error conditions that escalate the risk. Producing a denial of service may also be the goal of an attacker in itself. This issue is solved in Swift 5.6.2 for Linux and Windows. This issue was solved by ensuring that the same methods are invoked both when validating and during casting, so that no type mismatch occurs. Swift for Linux and Windows versions are not ABI-interchangeable. To upgrade a service, its owner must update to this version of the Swift toolchain, then recompile and redeploy their software. The new version of Swift includes an updated swift-corelibs-foundation package. Versions of Swift running on Darwin-based operating systems are not affected.

    Published: 16 Jun 2022
    9.8
    Critical

    CVE-2022-31384

    Last Modified: 21 Nov 2024

    Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

    Published: 16 Jun 2022
    5.5
    Medium

    CVE-2021-3675

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.

    Published: 16 Jun 2022