CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-17240

    Last Modified: 21 Nov 2024

    There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).

    Published: 10 Jun 2022
    6.1
    Medium

    CVE-2022-31402

    Last Modified: 21 Nov 2024

    ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.

    Published: 10 Jun 2022
    4.6
    Medium

    CVE-2022-29948

    Last Modified: 21 Nov 2024

    Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass attack that enables an attacker to gain access to the stored encrypted data. Normally, the encrypted disk partition with this data is unlocked by entering the correct passcode (6 to 14 digits) via the keypad and pressing the Unlock button. This authentication is performed by an unknown microcontroller. By replacing this microcontroller on a target device with one from an attacker-controlled Lepin EP-KP001 whose passcode is known, it is possible to successfully unlock the target device and read the stored data in cleartext.

    Published: 10 Jun 2022
    5.3
    Medium

    CVE-2022-31769

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration information stored in PostgreSQL, which could be used in further attacks against the system. IBM X-Force ID: 228219.

    Published: 10 Jun 2022
    5.4
    Medium

    CVE-2022-30611

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 227364.

    Published: 10 Jun 2022
    4.5
    Medium

    CVE-2022-30610

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 227363.

    Published: 10 Jun 2022
    8.8
    High

    CVE-2022-22479

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887.

    Published: 10 Jun 2022
    3.3
    Low

    CVE-2022-22426

    Last Modified: 21 Nov 2024

    IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass authentication and gain unauthorized access to the Spectrum Copy Data Management catalog which contains metadata. IBM X-Force ID: 223718.

    Published: 10 Jun 2022
    6.5
    Medium

    CVE-2022-32978

    Last Modified: 21 Nov 2024

    There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.

    Published: 10 Jun 2022
    8.8
    High

    CVE-2021-44117

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

    Published: 10 Jun 2022
    8.8
    High

    CVE-2021-44582

    Last Modified: 21 Nov 2024

    A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.

    Published: 10 Jun 2022
    9.8
    Critical

    CVE-2022-31788

    Last Modified: 21 Nov 2024

    IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.

    Published: 10 Jun 2022
    7.8
    High

    CVE-2022-27502

    Last Modified: 21 Nov 2024

    RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM.

    Published: 10 Jun 2022
    9.8
    Critical

    CVE-2022-32563

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials provided to the Admin REST API are ignored, resulting in privilege escalation for unauthenticated users. The Public REST API is not impacted by this issue. A workaround is to replace X.509 certificate based authentication with Username and Password authentication inside the bootstrap configuration.

    Published: 10 Jun 2022
    3.3
    Low

    CVE-2021-42811

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the underlying system on which the product is deployed.

    Published: 10 Jun 2022
    3.5
    Low

    CVE-2017-20036

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the file /lists/admin/ of the component Bounce Rule. The manipulation leads to cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    3.5
    Low

    CVE-2017-20035

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in PHPList 3.2.6. This issue affects some unknown processing of the file /lists/admin/ of the component Subscribe. The manipulation leads to cross site scripting (Persistent). The attack may be initiated remotely. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    3.5
    Low

    CVE-2017-20034

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in PHPList 3.2.6. This vulnerability affects unknown code of the file /lists/admin/ of the component List Name. The manipulation leads to cross site scripting (Persistent). The attack can be initiated remotely. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    4.3
    Medium

    CVE-2017-20033

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in PHPList 3.2.6. This affects an unknown part of the file /lists/admin/. The manipulation of the argument page with the input send\'\";><script>alert(8)</script> leads to cross site scripting (Reflected). It is possible to initiate the attack remotely. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    6.3
    Medium

    CVE-2017-20032

    Last Modified: 15 Apr 2025

    A vulnerability was found in PHPList 3.2.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Subscription. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    2.7
    Low

    CVE-2017-20031

    Last Modified: 15 Apr 2025

    A vulnerability was found in PHPList 3.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument sortby with the input password leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    4.7
    Medium

    CVE-2017-20030

    Last Modified: 15 Apr 2025

    A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the file /lists/admin/ of the component Sending Campain. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    7.3
    High

    CVE-2017-20029

    Last Modified: 15 Apr 2025

    A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 10 Jun 2022
    —
    Unknown

    CVE-2022-32952

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 10 Jun 2022
    7.8
    High

    CVE-2022-32981

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.

    Published: 10 Jun 2022
    7.8
    High

    CVE-2022-2042

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 8.2.

    Published: 10 Jun 2022
    8.1
    High

    CVE-2022-25845

    Last Modified: 21 Nov 2024

    The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

    Published: 10 Jun 2022
    7.5
    High

    CVE-2022-2414

    Last Modified: 21 Nov 2024

    Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potentially retrieve the content of arbitrary files by sending specially crafted HTTP requests.

    Published: 10 Jun 2022
    5.6
    Medium

    CVE-2017-20028

    Last Modified: 15 Apr 2025

    A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    4.3
    Medium

    CVE-2017-20027

    Last Modified: 15 Apr 2025

    A vulnerability was found in HumHub up to 1.0.1 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting (DOM). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    4.3
    Medium

    CVE-2017-20026

    Last Modified: 15 Apr 2025

    A vulnerability has been found in HumHub up to 1.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting (Reflected). The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    7.3
    High

    CVE-2017-20025

    Last Modified: 15 Apr 2025

    A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Flash Memory. The manipulation leads to privilege escalation. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    5.3
    Medium

    CVE-2017-20024

    Last Modified: 15 Apr 2025

    A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been classified as problematic. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    6.3
    Medium

    CVE-2017-20023

    Last Modified: 15 Apr 2025

    A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unknown processing of the component Network Config. The manipulation leads to privilege escalation. The attack may be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    7.5
    High

    CVE-2017-20022

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    6.5
    Medium

    CVE-2017-20021

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    5.3
    Medium

    CVE-2017-20020

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The attack may be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    4.3
    Medium

    CVE-2017-20019

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic was found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this vulnerability is an unknown functionality of the component Config Handler. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 9 Jun 2022
    6.3
    Medium

    CVE-2017-20018

    Last Modified: 15 Apr 2025

    A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.

    Published: 9 Jun 2022
    7
    High

    CVE-2022-31045

    Last Modified: 23 Apr 2025

    Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an Istio ingress Gateway exposed to external traffic. This vulnerability has been resolved in versions 1.12.8, 1.13.5, and 1.14.1. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 9 Jun 2022
    7.8
    High

    CVE-2022-30703

    Last Modified: 21 Nov 2024

    Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information. This vulnerability could also potentially be chained for privilege escalation.

    Published: 9 Jun 2022
    5.5
    Medium

    CVE-2022-30702

    Last Modified: 21 Nov 2024

    Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that could allow an attacker to disclose sensitive information on an affected machine.

    Published: 9 Jun 2022
    5.9
    Medium

    CVE-2022-31033

    Last Modified: 23 Apr 2025

    The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies, follows redirects, and can follow links and submit forms. In versions prior to 2.8.5 the Authorization header is leaked after a redirect to a different port on the same site. Users are advised to upgrade to Mechanize v2.8.5 or later. There are no known workarounds for this issue.

    Published: 9 Jun 2022
    8.1
    High

    CVE-2022-29250

    Last Modified: 23 Apr 2025

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulnerability a user must be logged in.

    Published: 9 Jun 2022
    6.5
    Medium

    CVE-2022-30898

    Last Modified: 21 Nov 2024

    A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.

    Published: 9 Jun 2022
    5.4
    Medium

    CVE-2022-24876

    Last Modified: 23 Apr 2025

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a cross site scripting vulnerability in Kanban by injecting HTML code in its user name. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 9 Jun 2022
    4.3
    Medium

    CVE-2022-30760

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.

    Published: 9 Jun 2022
    7.5
    High

    CVE-2022-23138

    Last Modified: 21 Nov 2024

    ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.

    Published: 9 Jun 2022
    6.1
    Medium

    CVE-2022-2035

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an attacker to craft malicious urls which can trigger a reflected XSS payload in the context of a victim's browser.

    Published: 9 Jun 2022
    7.5
    High

    CVE-2022-29225

    Last Modified: 22 Apr 2025

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small highly compressed payload. Maliciously constructed zip files may exhaust system memory and cause a denial of service. Users are advised to upgrade. Users unable to upgrade may consider disabling decompression.

    Published: 9 Jun 2022