CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2022-2018

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unknown function of the file /admin/?page=inmates/view_inmate of the component Inmate Handler. The manipulation of the argument id with the input 1%27%20and%201=2%20union%20select%201,user(),3,4,5,6,7,8,9,0,database(),2,3,4,5,6,7,8,9,0,1,2,3,4--+ leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2022
    4.7
    Medium

    CVE-2022-2017

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pms/admin/visits/view_visit.php of the component Visit Handler. The manipulation of the argument id with the input 2%27and%201=2%20union%20select%201,2,3,4,5,6,7,user(),database()--+ leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jun 2022
    5.4
    Medium

    CVE-2022-2016

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1.

    Published: 7 Jun 2022
    6.2
    Medium

    CVE-2022-0823

    Last Modified: 21 Nov 2024

    An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.

    Published: 7 Jun 2022
    4.5
    Medium

    CVE-2021-3696

    Last Modified: 21 Nov 2024

    A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

    Published: 7 Jun 2022
    9.8
    Critical

    CVE-2022-31031

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack buffer overflow vulnerability affects PJSIP users that use STUN in their applications, either by: setting a STUN server in their account/media config in PJSUA/PJSUA2 level, or directly using `pjlib-util/stun_simple` API. A patch is available in commit 450baca which should be included in the next release. There are no known workarounds for this issue.

    Published: 7 Jun 2022
    7.8
    High

    CVE-2022-2000

    Last Modified: 3 Nov 2025

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

    Published: 7 Jun 2022
    8.2
    High

    CVE-2022-1665

    Last Modified: 21 Nov 2024

    A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.

    Published: 7 Jun 2022
    8.1
    High

    CVE-2022-28733

    Last Modified: 13 Feb 2025

    Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

    Published: 7 Jun 2022
    6.1
    Medium

    CVE-2022-31470

    Last Modified: 21 Nov 2024

    An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.

    Published: 7 Jun 2022
    4.5
    Medium

    CVE-2021-3695

    Last Modified: 21 Nov 2024

    A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to achieve signifcant results, also the values written into the memory are repeated three times in a row making difficult to produce valid payloads. This flaw affects grub2 versions prior grub-2.12.

    Published: 7 Jun 2022
    7
    High

    CVE-2021-3697

    Last Modified: 21 Nov 2024

    A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

    Published: 7 Jun 2022
    6.1
    Medium

    CVE-2022-29296

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 6 Jun 2022
    6.1
    Medium

    CVE-2022-31494

    Last Modified: 21 Nov 2024

    LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.

    Published: 6 Jun 2022
    8.1
    High

    CVE-2022-27438

    Last Modified: 21 Nov 2024

    Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.

    Published: 6 Jun 2022
    5.4
    Medium

    CVE-2022-28051

    Last Modified: 21 Nov 2024

    The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.

    Published: 6 Jun 2022
    6.5
    Medium

    CVE-2022-28478

    Last Modified: 21 Nov 2024

    SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

    Published: 6 Jun 2022
    4.8
    Medium

    CVE-2022-28479

    Last Modified: 21 Nov 2024

    SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menu

    Published: 6 Jun 2022
    9.8
    Critical

    CVE-2022-30927

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable "id" parameter.

    Published: 6 Jun 2022
    6.1
    Medium

    CVE-2022-24969

    Last Modified: 21 Nov 2024

    bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.

    Published: 6 Jun 2022
    9.8
    Critical

    CVE-2022-32511

    Last Modified: 15 Jun 2026

    jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

    Published: 6 Jun 2022
    4.2
    Medium

    CVE-2022-31027

    Last Modified: 23 Apr 2025

    OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the *email* field provided to us by CILogon has a *domain* that matches one of the domains listed in `allowed_idps`.If `allowed_idps` contains `berkeley.edu`, you might expect only users with valid current credentials provided by University of California, Berkeley to be able to access the JupyterHub. However, CILogonOAuthenticator does *not* verify which provider is used by the user to login, only the email address provided. So a user can login with a GitHub account that has email set to `<something>@berkeley.edu`, and that will be treated exactly the same as someone logging in using the UC Berkeley official Identity Provider. The patch fixing this issue makes a *breaking change* in how `allowed_idps` is interpreted. It's no longer a list of domains, but configuration representing the `EntityID` of the IdPs that are allowed, picked from the [list maintained by CILogon](https://cilogon.org/idplist/). Users are advised to upgrade.

    Published: 6 Jun 2022
    7.5
    High

    CVE-2022-31019

    Last Modified: 22 Apr 2025

    Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request body that can make the server crash with the following request: `curl -d "array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n '[_0][0][array]'; done)[string][_0]=hello%20world" http://localhost:8080/foo`. The issue is unbounded, attacker controlled stack growth which will at some point lead to a stack overflow and a process crash. This issue has been fixed in version 4.61.1.

    Published: 6 Jun 2022
    5.9
    Medium

    CVE-2022-31026

    Last Modified: 23 Apr 2025

    Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to 12 bytes of data from an uninitialized variable in stack memory. Users of the trilogy gem should upgrade to version 2.1.1 This issue can be avoided by only connecting to trusted servers.

    Published: 6 Jun 2022
    6.1
    Medium

    CVE-2022-31498

    Last Modified: 21 Nov 2024

    LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.

    Published: 6 Jun 2022
    8.8
    High

    CVE-2022-30469

    Last Modified: 21 Nov 2024

    In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

    Published: 6 Jun 2022
    7.5
    High

    CVE-2022-29631

    Last Modified: 21 Nov 2024

    Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

    Published: 6 Jun 2022
    6.1
    Medium

    CVE-2022-31492

    Last Modified: 21 Nov 2024

    Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.

    Published: 6 Jun 2022
    8.2
    High

    CVE-2022-29255

    Last Modified: 22 Apr 2025

    Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling an external contract with no return value, the contract address (including side effects) could be evaluated twice. This may result in incorrect outcomes for contracts. This issue has been addressed in v0.3.4.

    Published: 6 Jun 2022
    7.5
    High

    CVE-2022-30587

    Last Modified: 21 Nov 2024

    Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.

    Published: 6 Jun 2022
    4.7
    Medium

    CVE-2020-6220

    Last Modified: 21 Nov 2024

    BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.

    Published: 6 Jun 2022
    6.5
    Medium

    CVE-2022-29617

    Last Modified: 21 Nov 2024

    Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application.

    Published: 6 Jun 2022
    3.7
    Low

    CVE-2022-29254

    Last Modified: 23 Apr 2025

    silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (those that use intermediary states like `isNotification()` or `isRedirect()`), if the payment identifier or success URL is exposed it is possible for payments to be prematurely marked as completed without payment being taken. This is mitigated by the fact that most payment gateways hide this information from users, however some issuing banks offer flawed 3DSecure implementations that may inadvertently expose this data. The following versions have been patched to fix this issue: `2.5.2`, `3.0.2`, `3.1.4`, and `3.2.1`. There are no known workarounds for this vulnerability.

    Published: 6 Jun 2022
    4.3
    Medium

    CVE-2022-24896

    Last Modified: 23 Apr 2025

    Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a tracker they cannot access as well as the name of the fields used in reports.

    Published: 6 Jun 2022
    9.1
    Critical

    CVE-2022-24840

    Last Modified: 22 Apr 2025

    django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location only. The issue was discovered by the maintainer. There were no reports of the vulnerability being known to or exploited by a third party, prior to the release of the patch. The vulnerability has been fixed in version 5.5.1 and above. There is no feasible workaround. We must urge all users to immediately updated to a patched version.

    Published: 6 Jun 2022
    7.2
    High

    CVE-2022-30586

    Last Modified: 21 Nov 2024

    Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.

    Published: 6 Jun 2022
    —
    Unknown

    CVE-2022-1550

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 6 Jun 2022
    6.1
    Medium

    CVE-2022-31493

    Last Modified: 21 Nov 2024

    LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.

    Published: 6 Jun 2022
    4.4
    Medium

    CVE-2022-21762

    Last Modified: 21 Nov 2024

    In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06477946; Issue ID: ALPS06477946.

    Published: 6 Jun 2022
    4.4
    Medium

    CVE-2022-21761

    Last Modified: 21 Nov 2024

    In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479532; Issue ID: ALPS06479532.

    Published: 6 Jun 2022
    4.4
    Medium

    CVE-2022-21760

    Last Modified: 21 Nov 2024

    In apusys driver, there is a possible system crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479562; Issue ID: ALPS06479562.

    Published: 6 Jun 2022
    6.7
    Medium

    CVE-2022-21759

    Last Modified: 21 Nov 2024

    In power service, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419106; Issue ID: ALPS06419077.

    Published: 6 Jun 2022
    6.7
    Medium

    CVE-2022-21758

    Last Modified: 21 Nov 2024

    In ccu, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06439600; Issue ID: ALPS06439600.

    Published: 6 Jun 2022
    7.5
    High

    CVE-2022-21757

    Last Modified: 21 Nov 2024

    In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06468894; Issue ID: ALPS06468894.

    Published: 6 Jun 2022
    4.4
    Medium

    CVE-2022-21756

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535950; Issue ID: ALPS06535950.

    Published: 6 Jun 2022
    4.4
    Medium

    CVE-2022-21755

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545464; Issue ID: ALPS06545464.

    Published: 6 Jun 2022
    6.7
    Medium

    CVE-2022-21754

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535953; Issue ID: ALPS06535953.

    Published: 6 Jun 2022
    6.7
    Medium

    CVE-2022-21753

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493899.

    Published: 6 Jun 2022
    6.7
    Medium

    CVE-2022-21752

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493873.

    Published: 6 Jun 2022
    6.7
    Medium

    CVE-2022-21751

    Last Modified: 21 Nov 2024

    In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511132; Issue ID: ALPS06511132.

    Published: 6 Jun 2022