CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2022-31974

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31975

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31976

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31977

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31978

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31980

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/manage_team&id=.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31981

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/view_team&id=.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31982

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31983

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31984

    Last Modified: 21 Nov 2024

    Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.

    Published: 1 Jun 2022
    6.5
    Medium

    CVE-2022-31966

    Last Modified: 21 Nov 2024

    ChatBot App with Suggestion v1.0 is vulnerable to Delete any file via /simple_chat_bot/classes/Master.php?f=delete_img.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31969

    Last Modified: 21 Nov 2024

    ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=user/manage_user&id=.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31970

    Last Modified: 21 Nov 2024

    ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/manage_response&id=.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31971

    Last Modified: 21 Nov 2024

    ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/view_response&id=.

    Published: 1 Jun 2022
    2.3
    Low

    CVE-2022-31000

    Last Modified: 22 Apr 2025

    solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to change the state of an order's adjustments if they hold its number, and the execution happens on a store administrator's computer. Users should upgrade to solidus_backend 3.1.6, 3.0.6, or 2.11.16 to receive a patch.

    Published: 1 Jun 2022
    8.8
    High

    CVE-2022-24848

    Last Modified: 23 Apr 2025

    DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?programs=` API endpoint in DHIS2 versions prior to 2.36.10.1 and 2.37.6.1. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user and requires a conscious attack to be exploited. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance's database. Security patches are now available for DHIS2 versions 2.36.10.1 and 2.37.6.1. One may apply mitigations at the web proxy level as a workaround. More information about these mitigations is available in the GitHub Security Advisory.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-29659

    Last Modified: 21 Nov 2024

    Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

    Published: 1 Jun 2022
    5.9
    Medium

    CVE-2022-1929

    Last Modified: 21 Nov 2024

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method

    Published: 1 Jun 2022
    5.9
    Medium

    CVE-2021-43308

    Last Modified: 21 Nov 2024

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function

    Published: 1 Jun 2022
    5.9
    Medium

    CVE-2021-43307

    Last Modified: 21 Nov 2024

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method

    Published: 1 Jun 2022
    5.9
    Medium

    CVE-2021-43306

    Last Modified: 21 Nov 2024

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method

    Published: 1 Jun 2022
    5.7
    Medium

    CVE-2022-30277

    Last Modified: 21 Nov 2024

    BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII).

    Published: 1 Jun 2022
    8.8
    High

    CVE-2022-22767

    Last Modified: 21 Nov 2024

    Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.

    Published: 1 Jun 2022
    9.1
    Critical

    CVE-2022-31945

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to Delete any file via /rdms/classes/Master.php?f=delete_img.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31946

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_team.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31948

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31951

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_respondent_type.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31952

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL injection via /rdms/classes/Master.php?f=delete_incident.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31953

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/view_report.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31956

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/manage_report.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31957

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/teams/view_team.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31959

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/teams/manage_team.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31961

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/manage_incident.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31962

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/view_incident.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31964

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/respondent_types/view_respondent_type.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31965

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/respondent_types/manage_respondent_type.php?id=.

    Published: 1 Jun 2022
    7.6
    High

    CVE-2021-27914

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject executable javascript

    Published: 1 Jun 2022
    7.8
    High

    CVE-2021-26635

    Last Modified: 21 Nov 2024

    In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerability to cause a stack buffer overflow and as a result, perform an attack such as remote code execution.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2021-26634

    Last Modified: 21 Nov 2024

    SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to perform attacks such as stealing server management rights using a web shell.

    Published: 1 Jun 2022
    7.5
    High

    CVE-2021-26633

    Last Modified: 21 Nov 2024

    SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file.

    Published: 1 Jun 2022
    —
    Unknown

    CVE-2021-4014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 Jun 2022
    8.8
    High

    CVE-2020-20971

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.

    Published: 1 Jun 2022
    7.5
    High

    CVE-2021-33254

    Last Modified: 21 Nov 2024

    An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.

    Published: 1 Jun 2022
    8.8
    High

    CVE-2021-34078

    Last Modified: 21 Nov 2024

    lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2021-34079

    Last Modified: 21 Nov 2024

    OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2021-34080

    Last Modified: 21 Nov 2024

    OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.

    Published: 1 Jun 2022
    8.8
    High

    CVE-2021-34081

    Last Modified: 21 Nov 2024

    OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2021-34082

    Last Modified: 21 Nov 2024

    OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.

    Published: 1 Jun 2022
    8.1
    High

    CVE-2021-34083

    Last Modified: 21 Nov 2024

    Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved from google to a shell command, potentially exposing the server to RCE.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2021-34084

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.

    Published: 1 Jun 2022