CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2022-22788

    Last Modified: 21 Nov 2024

    The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.

    Published: 15 Jun 2022
    5.5
    Medium

    CVE-2022-21180

    Last Modified: 5 May 2025

    Improper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local access.

    Published: 15 Jun 2022
    6.1
    Medium

    CVE-2021-41415

    Last Modified: 21 Nov 2024

    Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-21935

    Last Modified: 21 Nov 2024

    A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.

    Published: 15 Jun 2022
    5.4
    Medium

    CVE-2022-32280

    Last Modified: 20 Feb 2025

    Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Xakuro's XO Slider plugin <= 3.3.2 at WordPress.

    Published: 15 Jun 2022
    3.4
    Low

    CVE-2022-29452

    Last Modified: 20 Feb 2025

    Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32373

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam.php?id=.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2021-43755

    Last Modified: 23 Apr 2025

    Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32368

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_grade.php?id=.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32374

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject_routing.php?id=.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2021-42735

    Last Modified: 23 Apr 2025

    Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 15 Jun 2022
    9.8
    Critical

    CVE-2021-41418

    Last Modified: 21 Nov 2024

    AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.

    Published: 15 Jun 2022
    8.7
    High

    CVE-2022-21937

    Last Modified: 21 Nov 2024

    Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.

    Published: 15 Jun 2022
    5.4
    Medium

    CVE-2022-28612

    Last Modified: 20 Feb 2025

    Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28846

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    5.5
    Medium

    CVE-2022-28850

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28849

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28848

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28847

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28845

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28844

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28843

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28842

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28841

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28840

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28839

    Last Modified: 23 Apr 2025

    Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    5.4
    Medium

    CVE-2021-36891

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28225

    Last Modified: 21 Nov 2024

    Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-28226

    Last Modified: 21 Nov 2024

    Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2021-25261

    Last Modified: 21 Nov 2024

    Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.

    Published: 15 Jun 2022
    5.8
    Medium

    CVE-2022-31070

    Last Modified: 23 Apr 2025

    NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to block sensitive cookies (e.g. session cookies) from being forwarded to backend services configured by the application developer. This could have led to sensitive cookies being inadvertently exposed to such services that should not see them. The patched version now blocks cookies from being forwarded by default. However developers can configure an allow-list of cookie names by using the `allowedCookies` config setting. This issue has been fixed in version 0.7.0 of `@finastra/nestjs-proxy`. Users of `@ffdc/nestjs-proxy` are advised that this package has been deprecated and is no longer being maintained or receiving updates. Such users should update their package.json file to use `@finastra/nestjs-proxy` instead.

    Published: 15 Jun 2022
    7.5
    High

    CVE-2022-31044

    Last Modified: 23 Apr 2025

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using Rundeck 4.2.0 or 4.2.1 might result in them being written in plaintext to the backend storage. This affects those using any `Storage Converter` plugin. Rundeck 4.3.1 and 4.2.2 have fixed the code and upon upgrade will re-encrypt any plain text values. Version 4.3.0 does not have the vulnerability, but does not include the patch to re-encrypt plain text values if 4.2.0 or 4.2.1 were used. To prevent plaintext credentials from being stored in Rundeck 4.2.0/4.2.1, write access to key storage can be disabled via ACLs. After upgrading to 4.3.1 or later, write access can be restored.

    Published: 15 Jun 2022
    5.8
    Medium

    CVE-2022-31069

    Last Modified: 23 Apr 2025

    NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to control when Authorization headers should should be forwarded for specific backend services configured by the application developer. This could have resulted in sensitive information such as OAuth bearer access tokens being inadvertently exposed to such services that should not see them. A new feature has been introduced in the patched version of nestjs-proxy that allows application developers to opt out of forwarding the Authorization headers on a per service basis using the `forwardToken` config setting. Developers are advised to review the README for this library on Github or NPM for further details on how this configuration can be applied. This issue has been fixed in version 0.7.0 of `@finastra/nestjs-proxy`. Users of `@ffdc/nestjs-proxy` are advised that this package has been deprecated and is no longer being maintained or receiving updates. Such users should update their package.json file to use `@finastra/nestjs-proxy` instead.

    Published: 15 Jun 2022
    4.1
    Medium

    CVE-2022-29443

    Last Modified: 20 Feb 2025

    Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.

    Published: 15 Jun 2022
    5.4
    Medium

    CVE-2022-29450

    Last Modified: 23 Apr 2025

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.

    Published: 15 Jun 2022
    7.3
    High

    CVE-2022-31219

    Last Modified: 23 Apr 2025

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-31218

    Last Modified: 23 Apr 2025

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-31217

    Last Modified: 23 Apr 2025

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2022-31216

    Last Modified: 21 Nov 2024

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.

    Published: 15 Jun 2022
    6.7
    Medium

    CVE-2022-26057

    Last Modified: 21 Nov 2024

    Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a "repair" operation on the product

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32375

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32376

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32377

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam_timetable.php?id=.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32378

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher_profile.php?my_index=.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2021-43756

    Last Modified: 23 Apr 2025

    Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32379

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_parents_profile.php?my_index=.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32380

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_student_subject.php?index=.

    Published: 15 Jun 2022
    7.8
    High

    CVE-2021-43754

    Last Modified: 23 Apr 2025

    Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

    Published: 15 Jun 2022
    7.2
    High

    CVE-2022-32381

    Last Modified: 21 Nov 2024

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_admin_profile.php?my_index=.

    Published: 15 Jun 2022
    6.1
    Medium

    CVE-2021-40776

    Last Modified: 23 Apr 2025

    Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.

    Published: 15 Jun 2022