CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2022-32335

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=.

    Published: 14 Jun 2022
    7.2
    High

    CVE-2022-32334

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=.

    Published: 14 Jun 2022
    7.2
    High

    CVE-2022-32333

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=.

    Published: 14 Jun 2022
    7.2
    High

    CVE-2022-32332

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category.

    Published: 14 Jun 2022
    7.2
    High

    CVE-2022-32331

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=.

    Published: 14 Jun 2022
    7.2
    High

    CVE-2022-32330

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu.

    Published: 14 Jun 2022
    9.1
    Critical

    CVE-2022-32328

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.

    Published: 14 Jun 2022
    5.3
    Medium

    CVE-2022-27889

    Last Modified: 21 Nov 2024

    The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail for the duration of the attack. This could lead to performance degradation or login failures for customer Palantir Foundry environments. This vulnerability is resolved in Multipass 3.647.0. This issue affects: Palantir Foundry Multipass versions prior to 3.647.0.

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-40660

    Last Modified: 21 Nov 2024

    An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack.

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-31847

    Last Modified: 21 Nov 2024

    A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-31846

    Last Modified: 21 Nov 2024

    A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-31845

    Last Modified: 21 Nov 2024

    A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

    Published: 14 Jun 2022
    9.8
    Critical

    CVE-2022-31311

    Last Modified: 21 Nov 2024

    An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request.

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-31308

    Last Modified: 21 Nov 2024

    A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.191012 allows attackers to obtain sensitive router information via execution of the exec cmd function.

    Published: 14 Jun 2022
    7.5
    High

    CVE-2022-31309

    Last Modified: 21 Nov 2024

    A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive router information via execution of the exec cmd function.

    Published: 14 Jun 2022
    9.8
    Critical

    CVE-2022-32336

    Last Modified: 21 Nov 2024

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.

    Published: 14 Jun 2022
    5.4
    Medium

    CVE-2021-40678

    Last Modified: 21 Nov 2024

    In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

    Published: 14 Jun 2022
    9.8
    Critical

    CVE-2022-31273

    Last Modified: 21 Nov 2024

    An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force attack via a crafted session_id cookie.

    Published: 14 Jun 2022
    4.8
    Medium

    CVE-2021-40658

    Last Modified: 21 Nov 2024

    Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-35130

    Last Modified: 21 Nov 2024

    Memory corruption in graphics support layer due to use after free condition in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 14 Jun 2022
    7.8
    High

    CVE-2021-35129

    Last Modified: 21 Nov 2024

    Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-35126

    Last Modified: 21 Nov 2024

    Memory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    8.8
    High

    CVE-2021-35123

    Last Modified: 21 Nov 2024

    Buffer copy in GATT multi notification due to improper length check for the data coming over-the-air in Snapdragon Connectivity, Snapdragon Industrial IOT

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-35112

    Last Modified: 21 Nov 2024

    A user with user level permission can access graphics protected region due to improper access control in register configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    9.8
    Critical

    CVE-2021-35104

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to improper parsing of headers while playing the FLAC audio clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-35100

    Last Modified: 21 Nov 2024

    Possible buffer over read due to improper calculation of string length while parsing Id3 tag in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-35095

    Last Modified: 21 Nov 2024

    Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-35091

    Last Modified: 21 Nov 2024

    Possible out of bounds read due to improper typecasting while handling page fault for global memory in Snapdragon Connectivity, Snapdragon Mobile

    Published: 14 Jun 2022
    9.8
    Critical

    CVE-2021-35081

    Last Modified: 21 Nov 2024

    Possible buffer overflow due to improper validation of SSID length received from beacon or probe response during an IBSS session in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 14 Jun 2022
    5.5
    Medium

    CVE-2021-35071

    Last Modified: 21 Nov 2024

    Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2021-35070

    Last Modified: 21 Nov 2024

    RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-30350

    Last Modified: 21 Nov 2024

    Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

    Published: 14 Jun 2022
    8.2
    High

    CVE-2021-30349

    Last Modified: 21 Nov 2024

    Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    9.1
    Critical

    CVE-2021-30347

    Last Modified: 21 Nov 2024

    Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2021-30346

    Last Modified: 21 Nov 2024

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2021-30345

    Last Modified: 21 Nov 2024

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-30344

    Last Modified: 21 Nov 2024

    Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    9.1
    Critical

    CVE-2021-30343

    Last Modified: 21 Nov 2024

    Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    9.1
    Critical

    CVE-2021-30342

    Last Modified: 21 Nov 2024

    Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    9.8
    Critical

    CVE-2021-30341

    Last Modified: 21 Nov 2024

    Improper buffer size validation of DSM packet received can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-30340

    Last Modified: 21 Nov 2024

    Reachable assertion due to improper validation of coreset in PDCCH configuration in SA mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 14 Jun 2022
    9
    Critical

    CVE-2021-30339

    Last Modified: 21 Nov 2024

    Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    7.1
    High

    CVE-2021-30338

    Last Modified: 21 Nov 2024

    Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-30334

    Last Modified: 21 Nov 2024

    Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022
    7.5
    High

    CVE-2021-30327

    Last Modified: 21 Nov 2024

    Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music

    Published: 14 Jun 2022
    8.4
    High

    CVE-2021-30281

    Last Modified: 21 Nov 2024

    Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 14 Jun 2022
    6.5
    Medium

    CVE-2021-40616

    Last Modified: 21 Nov 2024

    thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.

    Published: 14 Jun 2022
    7.8
    High

    CVE-2022-22072

    Last Modified: 21 Nov 2024

    Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 14 Jun 2022
    8.4
    High

    CVE-2022-22071

    Last Modified: 28 Oct 2025

    Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 14 Jun 2022
    8.4
    High

    CVE-2022-22068

    Last Modified: 21 Nov 2024

    kernel event may contain unexpected content which is not generated by NPU software in asynchronous execution mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 14 Jun 2022