CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2017-20043

    Last Modified: 15 Apr 2025

    A vulnerability was found in Navetti PricePoint 4.6.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting (Persistent). The attack may be launched remotely. Upgrading to version 4.7.0.0 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 13 Jun 2022
    6.3
    Medium

    CVE-2017-20042

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Navetti PricePoint 4.6.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection (Blind). The attack can be launched remotely. Upgrading to version 4.7.0.0 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 13 Jun 2022
    5.4
    Medium

    CVE-2017-20041

    Last Modified: 15 Apr 2025

    A vulnerability was found in Ucweb UC Browser 11.2.5.932. It has been classified as critical. Affected is an unknown function of the component HTML Handler. The manipulation of the argument title leads to improper restriction of rendered ui layers (URL). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jun 2022
    4.8
    Medium

    CVE-2022-29894

    Last Modified: 21 Nov 2024

    Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2022-29525

    Last Modified: 21 Nov 2024

    Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.

    Published: 13 Jun 2022
    7.2
    High

    CVE-2022-28704

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN side, and is also connected to the Internet with the authentication information unchanged from the default settings.

    Published: 13 Jun 2022
    6.1
    Medium

    CVE-2022-27231

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.

    Published: 13 Jun 2022
    4.3
    Medium

    CVE-2022-27174

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a category via a specially crafted page.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-26834

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default.

    Published: 13 Jun 2022
    6.5
    Medium

    CVE-2022-26041

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server via unspecified vectors.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-2062

    Last Modified: 26 Aug 2025

    Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

    Published: 13 Jun 2022
    —
    Unknown

    CVE-2022-33010

    Last Modified: 3 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 13 Jun 2022
    5.5
    Medium

    CVE-2022-3598

    Last Modified: 7 May 2025

    LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.

    Published: 13 Jun 2022
    9.8
    Critical

    CVE-2021-37404

    Last Modified: 21 Nov 2024

    There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-29244

    Last Modified: 23 Apr 2025

    npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.

    Published: 13 Jun 2022
    7.5
    High

    CVE-2022-2013

    Last Modified: 21 Nov 2024

    In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space.

    Published: 12 Jun 2022
    8.4
    High

    CVE-2022-2054

    Last Modified: 25 Feb 2026

    Code Injection in GitHub repository nuitka/nuitka prior to 0.9.

    Published: 12 Jun 2022
    8.4
    High

    CVE-2021-41641

    Last Modified: 21 Nov 2024

    Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

    Published: 12 Jun 2022
    6.1
    Medium

    CVE-2021-41750

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page / file and fileName parameter containing an arbitrary filename with the intended content-type to be rendered in the user's browser as the extension.

    Published: 12 Jun 2022
    9.8
    Critical

    CVE-2021-41749

    Last Modified: 21 Nov 2024

    In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.

    Published: 12 Jun 2022
    3.5
    Low

    CVE-2018-25039

    Last Modified: 15 Apr 2025

    A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/RgUrlBlock.asp. The manipulation of the argument BasicParentalNewKeyword with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jun 2022
    3.5
    Low

    CVE-2018-25038

    Last Modified: 15 Apr 2025

    A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown part of the file /goform/RgDhcp. The manipulation of the argument PppUserName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jun 2022
    3.5
    Low

    CVE-2018-25037

    Last Modified: 15 Apr 2025

    A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/RgDdns. The manipulation of the argument DdnsHostName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jun 2022
    3.5
    Low

    CVE-2018-25036

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/RgTime. The manipulation of the argument TimeServer1/TimeServer2/TimeServer3 with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jun 2022
    3.5
    Low

    CVE-2018-25035

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05. Affected is an unknown function of the file /goform/RGFirewallEL. The manipulation of the argument EmailAddress/SmtpServerName with the input ><script>alert(1)</script> as part of POST Request leads to cross site scripting (Persistent). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Jun 2022
    3.5
    Low

    CVE-2018-25034

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in Thomson TCW710 ST5D.10.05. This issue affects some unknown processing of the file /goform/wlanPrimaryNetwork. The manipulation of the argument ServiceSetIdentifier with the input ><script>alert(1)</script> as part of POST Request leads to basic cross site scripting (Persistent). The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-126695.

    Published: 12 Jun 2022
    6.1
    Medium

    CVE-2021-44266

    Last Modified: 21 Nov 2024

    GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.

    Published: 11 Jun 2022
    7.5
    High

    CVE-2022-30780

    Last Modified: 21 Nov 2024

    Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.

    Published: 11 Jun 2022
    5.4
    Medium

    CVE-2021-41502

    Last Modified: 21 Nov 2024

    An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.

    Published: 11 Jun 2022
    8.8
    High

    CVE-2021-41738

    Last Modified: 21 Nov 2024

    ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

    Published: 11 Jun 2022
    5.9
    Medium

    CVE-2017-20040

    Last Modified: 15 Apr 2025

    A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been declared as problematic. This vulnerability affects unknown code of the component Password Storage. The manipulation leads to weak encryption. Attacking locally is a requirement.

    Published: 11 Jun 2022
    9.8
    Critical

    CVE-2017-20039

    Last Modified: 15 Apr 2025

    A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely.

    Published: 11 Jun 2022
    6.3
    Medium

    CVE-2017-20038

    Last Modified: 15 Apr 2025

    A vulnerability was found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this issue is some unknown functionality of the file card_scan_decoder.php. The manipulation of the argument No/door leads to privilege escalation. The attack may be launched remotely.

    Published: 11 Jun 2022
    6.3
    Medium

    CVE-2017-20037

    Last Modified: 15 Apr 2025

    A vulnerability has been found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument c leads to privilege escalation. The attack can be launched remotely.

    Published: 11 Jun 2022
    9.8
    Critical

    CVE-2021-41756

    Last Modified: 21 Nov 2024

    dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.

    Published: 10 Jun 2022
    9.8
    Critical

    CVE-2021-41755

    Last Modified: 21 Nov 2024

    dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.

    Published: 10 Jun 2022
    9.8
    Critical

    CVE-2021-41754

    Last Modified: 21 Nov 2024

    dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.

    Published: 10 Jun 2022
    7.5
    High

    CVE-2022-25851

    Last Modified: 21 Nov 2024

    The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.

    Published: 10 Jun 2022
    5.9
    Medium

    CVE-2022-21211

    Last Modified: 21 Nov 2024

    This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the value of toString is not invokable (not a function), and then it will crash with type-check.

    Published: 10 Jun 2022
    7.5
    High

    CVE-2022-24278

    Last Modified: 21 Nov 2024

    The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

    Published: 10 Jun 2022
    7.2
    High

    CVE-2022-24376

    Last Modified: 21 Nov 2024

    All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package. **Note:** Please note that the vulnerability will not be fixed. The README file was updated with a warning regarding this issue.

    Published: 10 Jun 2022
    8.3
    High

    CVE-2022-29095

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system.

    Published: 10 Jun 2022
    7.1
    High

    CVE-2022-29094

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system.

    Published: 10 Jun 2022
    7.1
    High

    CVE-2022-29093

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.

    Published: 10 Jun 2022
    7.8
    High

    CVE-2022-29092

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.

    Published: 10 Jun 2022
    7.5
    High

    CVE-2022-24429

    Last Modified: 21 Nov 2024

    The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.

    Published: 10 Jun 2022
    8.1
    High

    CVE-2022-25863

    Last Modified: 29 Sept 2026

    The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this vulnerability is possible when passing input in both webpack (MDX files in src/pages or MDX file imported as a component in frontend / React code) and data mode (querying MDX nodes via GraphQL). Workaround: If an older version of gatsby-plugin-mdx must be used, input passed into the plugin should be sanitized ahead of processing.

    Published: 10 Jun 2022
    5.5
    Medium

    CVE-2022-31287

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.

    Published: 10 Jun 2022
    5.5
    Medium

    CVE-2022-31285

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.

    Published: 10 Jun 2022
    5.5
    Medium

    CVE-2022-31282

    Last Modified: 21 Nov 2024

    Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.

    Published: 10 Jun 2022