CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-32278

    Last Modified: 21 Nov 2024

    XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.

    Published: 13 Jun 2022
    6.6
    Medium

    CVE-2022-29257

    Last Modified: 23 Apr 2025

    Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto updating infrastructure and the ease of that attack entirely depends on the potential victim's infrastructure security. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. There are no known workarounds.

    Published: 13 Jun 2022
    2.2
    Low

    CVE-2022-29247

    Last Modified: 23 Apr 2025

    Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with `nodeIntegrationInSubFrames` enabled which in turn allows effective access to `ipcRenderer`. The `nodeIntegrationInSubFrames` option does not implicitly grant Node.js access. Rather, it depends on the existing sandbox setting. If an application is sandboxed, then `nodeIntegrationInSubFrames` just gives access to the sandboxed renderer APIs, which include `ipcRenderer`. If the application then additionally exposes IPC messages without IPC `senderFrame` validation that perform privileged actions or return confidential data this access to `ipcRenderer` can in turn compromise your application / user even with the sandbox enabled. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. As a workaround, ensure that all IPC message handlers appropriately validate `senderFrame`.

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-32193

    Last Modified: 21 Nov 2024

    Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-32558

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-32560

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-32564

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-31054

    Last Modified: 23 Apr 2025

    Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. `ioutil.ReadAll()` reads all the data into memory. As such, an attacker who sends a large request to the Argo Events server will be able to crash it and cause denial of service. A patch for this vulnerability has been released in Argo Events version 1.7.1.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-31053

    Last Modified: 22 Apr 2025

    Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any access level. The version 2 of the specification mandates a different algorithm than gamma signatures and as such is not affected by this vulnerability. The Biscuit implementations in Rust, Haskell, Go, Java and Javascript all have published versions following the v2 specification. There are no known workarounds for this issue.

    Published: 13 Jun 2022
    6.8
    Medium

    CVE-2022-22259

    Last Modified: 21 Nov 2024

    There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-29797

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability may lead to privilege escalation.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-29798

    Last Modified: 21 Nov 2024

    There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation could cause denial of service.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2021-40036

    Last Modified: 21 Nov 2024

    The bone voice ID TA has a memory overwrite vulnerability. Successful exploitation of this vulnerability may result in malicious code execution.

    Published: 13 Jun 2022
    9.1
    Critical

    CVE-2021-40604

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user.

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2021-41663

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-33174

    Last Modified: 21 Nov 2024

    Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-33175

    Last Modified: 21 Nov 2024

    Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41454

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41452

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41453

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41448

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41447

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41439

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41446

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-41438

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jun 2022
    5.9
    Medium

    CVE-2022-23169

    Last Modified: 21 Nov 2024

    attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.

    Published: 13 Jun 2022
    5.9
    Medium

    CVE-2022-23168

    Last Modified: 21 Nov 2024

    The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'--

    Published: 13 Jun 2022
    5.3
    Medium

    CVE-2022-23167

    Last Modified: 21 Nov 2024

    Attacker crafts a GET request to: /mobile/downloadfile.aspx? Filename =../.. /windows/boot.ini the LFI is UNAUTHENTICATED.

    Published: 13 Jun 2022
    4.7
    Medium

    CVE-2022-29455

    Last Modified: 20 Feb 2025

    DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-28217

    Last Modified: 21 Nov 2024

    Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-31055

    Last Modified: 23 Apr 2025

    kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who want to test challenges privately can mark them as `public: false` and use `kctf chal debug port-forward` to connect.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-31752

    Last Modified: 21 Nov 2024

    Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-31761

    Last Modified: 21 Nov 2024

    Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality.

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2021-46815

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-46789. Reason: This candidate is a duplicate of CVE-2021-46789. Notes: All CVE users should reference CVE-2021-46789 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Jun 2022
    7.5
    High

    CVE-2021-46813

    Last Modified: 21 Nov 2024

    Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-31754

    Last Modified: 21 Nov 2024

    Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the availability of some features.

    Published: 13 Jun 2022
    5.3
    Medium

    CVE-2021-46811

    Last Modified: 21 Nov 2024

    HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-31753

    Last Modified: 21 Nov 2024

    The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of this vulnerability may affect system availability.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-31757

    Last Modified: 21 Nov 2024

    The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2021-46812

    Last Modified: 21 Nov 2024

    The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity.

    Published: 13 Jun 2022
    9.1
    Critical

    CVE-2022-31760

    Last Modified: 21 Nov 2024

    Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.

    Published: 13 Jun 2022
    7.8
    High

    CVE-2022-31762

    Last Modified: 21 Nov 2024

    The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-31759

    Last Modified: 21 Nov 2024

    AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affect system availability.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-31755

    Last Modified: 21 Nov 2024

    The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-31756

    Last Modified: 21 Nov 2024

    The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-31751

    Last Modified: 21 Nov 2024

    The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system availability.

    Published: 13 Jun 2022
    4.7
    Medium

    CVE-2022-31758

    Last Modified: 21 Nov 2024

    The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-31763

    Last Modified: 21 Nov 2024

    The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2021-46814

    Last Modified: 21 Nov 2024

    The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-30311

    Last Modified: 21 Nov 2024

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

    Published: 13 Jun 2022