CVE Feed

    Dashboard / CVE

    9.4
    Critical

    CVE-2022-30234

    Last Modified: 21 Nov 2024

    A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

    Published: 2 Jun 2022
    6.5
    Medium

    CVE-2022-30233

    Last Modified: 21 Nov 2024

    A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when the user is tricked into performing certain actions on a webpage. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

    Published: 2 Jun 2022
    8
    High

    CVE-2022-30232

    Last Modified: 21 Nov 2024

    A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

    Published: 2 Jun 2022
    7.8
    High

    CVE-2022-29594

    Last Modified: 21 Nov 2024

    eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.

    Published: 2 Jun 2022
    6.1
    Medium

    CVE-2023-4958

    Last Modified: 21 Nov 2024

    In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.

    Published: 2 Jun 2022
    7.4
    High

    CVE-2022-31459

    Last Modified: 21 Nov 2024

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.

    Published: 2 Jun 2022
    7.4
    High

    CVE-2022-31461

    Last Modified: 21 Nov 2024

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message.

    Published: 2 Jun 2022
    9.3
    Critical

    CVE-2022-31462

    Last Modified: 21 Nov 2024

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.

    Published: 2 Jun 2022
    8.2
    High

    CVE-2022-31463

    Last Modified: 21 Nov 2024

    Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used.

    Published: 2 Jun 2022
    7.4
    High

    CVE-2022-31460

    Last Modified: 21 Nov 2024

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value.

    Published: 2 Jun 2022
    6.4
    Medium

    CVE-2022-29085

    Last Modified: 21 Nov 2024

    Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.

    Published: 2 Jun 2022
    8.1
    High

    CVE-2022-29084

    Last Modified: 21 Nov 2024

    Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-26869

    Last Modified: 21 Nov 2024

    Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and arbitrary code execution.

    Published: 2 Jun 2022
    6.4
    Medium

    CVE-2022-26868

    Last Modified: 21 Nov 2024

    Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system takeover by an attacker.

    Published: 2 Jun 2022
    5.9
    Medium

    CVE-2022-26867

    Last Modified: 21 Nov 2024

    PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, without any validation or sanitization. It allows a malicious, authenticated user to inject payloads that might get interpreted as formulas by the corresponding spreadsheet application that is being used to open the CSV/XLSX file.

    Published: 2 Jun 2022
    5.5
    Medium

    CVE-2022-26866

    Last Modified: 21 Nov 2024

    Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

    Published: 2 Jun 2022
    7.5
    High

    CVE-2022-22557

    Last Modified: 21 Nov 2024

    PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

    Published: 2 Jun 2022
    3.7
    Low

    CVE-2022-22556

    Last Modified: 21 Nov 2024

    Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service.

    Published: 2 Jun 2022
    9.1
    Critical

    CVE-2021-33473

    Last Modified: 21 Nov 2024

    An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is exploited via a crafted URL.

    Published: 2 Jun 2022
    7.5
    High

    CVE-2021-42877

    Last Modified: 21 Nov 2024

    TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2021-42875

    Last Modified: 21 Nov 2024

    TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.

    Published: 2 Jun 2022
    6.5
    Medium

    CVE-2022-31024

    Last Modified: 23 Apr 2025

    richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and 4.2.6 contain a fix for this issue. There are currently no known workarounds available.

    Published: 2 Jun 2022
    5.9
    Medium

    CVE-2022-31023

    Last Modified: 23 Apr 2025

    Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when run in dev mode, shows verbose errors for easy debugging, including an exception stack trace. Play does this by configuring its `DefaultHttpErrorHandler` to do so based on the application mode. In its Scala API Play also provides a static object `DefaultHttpErrorHandler` that is configured to always show verbose errors. This is used as a default value in some Play APIs, so it is possible to inadvertently use this version in production. It is also possible to improperly configure the `DefaultHttpErrorHandler` object instance as the injected error handler. Both of these situations could result in verbose errors displaying to users in a production application, which could expose sensitive information from the application. In particular, the constructor for `CORSFilter` and `apply` method for `CORSActionBuilder` use the static object `DefaultHttpErrorHandler` as a default value. This is patched in Play Framework 2.8.16. The `DefaultHttpErrorHandler` object has been changed to use the prod-mode behavior, and `DevHttpErrorHandler` has been introduced for the dev-mode behavior. A workaround is available. When constructing a `CORSFilter` or `CORSActionBuilder`, ensure that a properly-configured error handler is passed. Generally this should be done by using the `HttpErrorHandler` instance provided through dependency injection or through Play's `BuiltInComponents`. Ensure that the application is not using the `DefaultHttpErrorHandler` static object in any code that may be run in production.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2021-45983

    Last Modified: 21 Nov 2024

    NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.

    Published: 2 Jun 2022
    8.8
    High

    CVE-2021-45982

    Last Modified: 21 Nov 2024

    NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2021-45981

    Last Modified: 21 Nov 2024

    NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.

    Published: 2 Jun 2022
    6.5
    Medium

    CVE-2022-26944

    Last Modified: 21 Nov 2024

    Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table. NOTE: this issue exists because of an incomplete fix for CVE-2020-10997.

    Published: 2 Jun 2022
    5.4
    Medium

    CVE-2021-38221

    Last Modified: 21 Nov 2024

    bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.

    Published: 2 Jun 2022
    2.4
    Low

    CVE-2022-1980

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been rated as problematic. This issue affects the file /admin/?page=system_info/contact_info. The manipulation of the textbox Telephone with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but requires authentication. Exploit details have been disclosed to the public.

    Published: 2 Jun 2022
    3.5
    Low

    CVE-2022-1979

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulnerability affects p=contact. The manipulation of the Message textbox with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires authentication. Exploit details have been disclosed to the public.

    Published: 2 Jun 2022
    5.4
    Medium

    CVE-2022-30429

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found in versions 3.3.29 and 8.0.1 and could also be present in all intermediate versions.

    Published: 2 Jun 2022
    6.5
    Medium

    CVE-2022-29597

    Last Modified: 21 Nov 2024

    Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of the internal system file requested. This ability could allow for adversaries to extract sensitive data and/or files from the underlying file system, gain knowledge about the internal workings of the system, or access source code of the application.

    Published: 2 Jun 2022
    4.6
    Medium

    CVE-2022-1716

    Last Modified: 21 Nov 2024

    Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

    Published: 2 Jun 2022
    4.3
    Medium

    CVE-2022-1982

    Last Modified: 6 Dec 2024

    Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-25163

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial number "24061" or prior, Mitsubishi Electric MELSEC-L series LJ71E71-100 first 5 digits of serial number "24061" or prior and Mitsubishi Electric MELSEC iQ-R Series RD81MES96N firmware version "08" or prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or execute malicious code on the target products by sending specially crafted packets.

    Published: 2 Jun 2022
    7.5
    High

    CVE-2022-31018

    Last Modified: 23 Apr 2025

    Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` method on a JSON request body or the `Form#bind` method directly on a JSON value. If the JSON data being bound to the form contains a deeply-nested JSON object or array, the form binding implementation may consume all available heap space and cause an `OutOfMemoryError`. If executing on the default dispatcher and `akka.jvm-exit-on-fatal-error` is enabled—as it is by default—then this can crash the application process. `Form.bindFromRequest` is vulnerable when using any body parser that produces a type of `AnyContent` or `JsValue` in Scala, or one that can produce a `JsonNode` in Java. This includes Play's default body parser. This vulnerability been patched in version 2.8.16. There is now a global limit on the depth of a JSON object that can be parsed, which can be configured by the user if necessary. As a workaround, applications that do not need to parse a request body of type `application/json` can switch from the default body parser to another body parser that supports only the specific type of body they expect.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-29704

    Last Modified: 21 Nov 2024

    BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-32019

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.

    Published: 2 Jun 2022
    9.8
    Critical

    CVE-2022-32020

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via ip/car-rental-management-system/admin/ajax.php?action=save_settings.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32021

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32022

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32024

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32025

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32026

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32027

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=manage_car&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32028

    Last Modified: 21 Nov 2024

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32007

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32008

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/vacancy/index.php?view=edit&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32010

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/user/index.php?view=edit&id=.

    Published: 2 Jun 2022
    7.2
    High

    CVE-2022-32011

    Last Modified: 21 Nov 2024

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/applicants/index.php?view=view&id=.

    Published: 2 Jun 2022