CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-30923

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTimingtimeWifiAndLed parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30921

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetMobileAPInfoById parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30920

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30918

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnet parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30919

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID_5G parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30917

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddWlanMacList parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30916

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnetDebug parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30914

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateMacClone parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30915

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateSnat parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30913

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the ipqos_set_bandwidth parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30912

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateWanParams parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30910

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the GO parameter at /goform/aspForm.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-30909

    Last Modified: 21 Nov 2024

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the CMD parameter at /goform/aspForm.

    Published: 8 Jun 2022
    5.5
    Medium

    CVE-2022-30552

    Last Modified: 12 May 2026

    Das U-Boot 2022.01 has a Buffer Overflow.

    Published: 8 Jun 2022
    7.8
    High

    CVE-2022-30790

    Last Modified: 12 May 2026

    Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.

    Published: 8 Jun 2022
    6.1
    Medium

    CVE-2022-31497

    Last Modified: 21 Nov 2024

    LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.

    Published: 8 Jun 2022
    5.4
    Medium

    CVE-2022-2026

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.

    Published: 8 Jun 2022
    8
    High

    CVE-2022-2027

    Last Modified: 21 Nov 2024

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

    Published: 8 Jun 2022
    5.4
    Medium

    CVE-2022-2028

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.

    Published: 8 Jun 2022
    5.4
    Medium

    CVE-2022-2029

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.

    Published: 8 Jun 2022
    5.4
    Medium

    CVE-2022-2015

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.

    Published: 8 Jun 2022
    5.4
    Medium

    CVE-2022-2014

    Last Modified: 21 Nov 2024

    Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.

    Published: 8 Jun 2022
    9.1
    Critical

    CVE-2022-28615

    Last Modified: 18 Dec 2025

    Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.

    Published: 8 Jun 2022
    7.1
    High

    CVE-2022-1973

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem.

    Published: 8 Jun 2022
    7.8
    High

    CVE-2022-25153

    Last Modified: 11 Mar 2025

    The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup.

    Published: 8 Jun 2022
    5.3
    Medium

    CVE-2022-28330

    Last Modified: 21 Nov 2024

    Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

    Published: 8 Jun 2022
    4.6
    Medium

    CVE-2022-28386

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring a reformat of the drive after 20 failed unlock attempts) does not work as specified. More than 20 attempts may be made. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428 and Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0.

    Published: 8 Jun 2022
    5.3
    Medium

    CVE-2022-28614

    Last Modified: 21 Nov 2024

    The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.

    Published: 8 Jun 2022
    7.5
    High

    CVE-2022-30522

    Last Modified: 21 Nov 2024

    If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

    Published: 8 Jun 2022
    5.5
    Medium

    CVE-2021-40592

    Last Modified: 21 Nov 2024

    GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreachable exit condition ('infinite loop') vulnerability in ISOBMFF reader filter, isoffin_read.c. Function isoffin_process() can result in DoS by infinite loop. To exploit, the victim must open a specially crafted mp4 file.

    Published: 8 Jun 2022
    7.5
    High

    CVE-2022-25151

    Last Modified: 11 Mar 2025

    Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.

    Published: 8 Jun 2022
    9.9
    Critical

    CVE-2022-25152

    Last Modified: 11 Mar 2025

    The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a malicious actor (with a valid session token) can create a procedure, bypass approval, and execute the procedure. This results in the ability for any user with a valid session token to perform arbitrary code execution and full system take-over on all agents.

    Published: 8 Jun 2022
    7.5
    High

    CVE-2022-26377

    Last Modified: 1 May 2025

    Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.

    Published: 8 Jun 2022
    7.5
    High

    CVE-2022-28382

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The firmware of the USB-to-SATA bridge controller INIC-3637EN uses AES-256 with the ECB mode. This operation mode of block ciphers (e.g., AES) always encrypts identical plaintext data, in this case blocks of 16 bytes, to identical ciphertext data. For some data, for instance bitmap images, the lack of the cryptographic property called diffusion, within ECB, can leak sensitive information even in encrypted data. Thus, the use of the ECB operation mode can put the confidentiality of specific information at risk, even in an encrypted form. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.

    Published: 8 Jun 2022
    5.5
    Medium

    CVE-2022-28384

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline brute-force attack for determining the correct passcode, and thus gaining unauthorized access to the stored encrypted data. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428 and Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0.

    Published: 8 Jun 2022
    7.5
    High

    CVE-2022-29404

    Last Modified: 21 Nov 2024

    In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

    Published: 8 Jun 2022
    7.5
    High

    CVE-2022-30556

    Last Modified: 1 May 2025

    Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.

    Published: 8 Jun 2022
    6.8
    Medium

    CVE-2022-28383

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attacker can store malicious firmware code for the USB-to-SATA bridge controller on the USB drive (e.g., by leveraging physical access during the supply chain). This code is then executed. This affects Keypad Secure USB 3.2 Gen 1 Drive Part Number #49428, Store 'n' Go Secure Portable HDD GD25LK01-3637-C VER4.0, Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1, and Fingerprint Secure Portable Hard Drive Part Number #53650.

    Published: 8 Jun 2022
    9.8
    Critical

    CVE-2022-31813

    Last Modified: 1 May 2025

    Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

    Published: 8 Jun 2022
    6
    Medium

    CVE-2021-35530

    Last Modified: 21 Nov 2024

    A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token validation of the session identifier, allows an unauthorized modified message to be executed in the server enabling an unauthorized actor to change an existing user password, and further gain authorized access into the system via login mechanism. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0 2.1.0; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.

    Published: 7 Jun 2022
    6.5
    Medium

    CVE-2022-30466

    Last Modified: 21 Nov 2024

    joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay.

    Published: 7 Jun 2022
    6.5
    Medium

    CVE-2022-29620

    Last Modified: 21 Nov 2024

    FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability

    Published: 7 Jun 2022
    6.7
    Medium

    CVE-2021-35531

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights to inject an OS command that is executed by the system. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0; 2.0.1; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.

    Published: 7 Jun 2022
    6.7
    Medium

    CVE-2021-35532

    Last Modified: 21 Nov 2024

    A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an account with sufficient privilege to upload a malicious firmware to the product. This issue affects: Hitachi Energy TXpert Hub CoreTec 4 version 2.0.0; 2.0.1; 2.1.0; 2.1.1; 2.1.2; 2.1.3; 2.2.0; 2.2.1.

    Published: 7 Jun 2022
    3.3
    Low

    CVE-2022-30749

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30748

    Last Modified: 21 Nov 2024

    Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.

    Published: 7 Jun 2022
    5.5
    Medium

    CVE-2022-30747

    Last Modified: 21 Nov 2024

    PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.

    Published: 7 Jun 2022
    7.5
    High

    CVE-2022-30746

    Last Modified: 21 Nov 2024

    Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

    Published: 7 Jun 2022
    4
    Medium

    CVE-2022-30745

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.

    Published: 7 Jun 2022
    6.2
    Medium

    CVE-2022-30744

    Last Modified: 21 Nov 2024

    DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.

    Published: 7 Jun 2022