CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-30470

    Last Modified: 21 Nov 2024

    In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.

    Published: 1 Jun 2022
    8.1
    High

    CVE-2022-29098

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.

    Published: 1 Jun 2022
    7.5
    High

    CVE-2020-26185

    Last Modified: 21 Nov 2024

    Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.

    Published: 1 Jun 2022
    7.5
    High

    CVE-2020-26184

    Last Modified: 21 Nov 2024

    Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.

    Published: 1 Jun 2022
    6.1
    Medium

    CVE-2022-23237

    Last Modified: 21 Nov 2024

    E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

    Published: 1 Jun 2022
    4.4
    Medium

    CVE-2022-23236

    Last Modified: 21 Nov 2024

    E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.

    Published: 1 Jun 2022
    7.8
    High

    CVE-2022-30540

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code

    Published: 1 Jun 2022
    6.5
    Medium

    CVE-2022-31342

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to Delete any file via /ocwbs/classes/Master.php?f=delete_img.

    Published: 1 Jun 2022
    7.8
    High

    CVE-2022-29488

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code.

    Published: 1 Jun 2022
    7.8
    High

    CVE-2022-28690

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31343

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=.

    Published: 1 Jun 2022
    7.8
    High

    CVE-2022-27184

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31344

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_booking.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31345

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31346

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_service.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31347

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31348

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/update_status.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31350

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31351

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31352

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31353

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/services/view_service.php?id=.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31354

    Last Modified: 18 Feb 2026

    Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2022-31339

    Last Modified: 21 Nov 2024

    Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-31340

    Last Modified: 21 Nov 2024

    Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-29777

    Last Modified: 21 Nov 2024

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-29776

    Last Modified: 21 Nov 2024

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.

    Published: 1 Jun 2022
    6.1
    Medium

    CVE-2022-26978

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.

    Published: 1 Jun 2022
    6.1
    Medium

    CVE-2022-26977

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS.

    Published: 1 Jun 2022
    5.4
    Medium

    CVE-2022-26976

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.

    Published: 1 Jun 2022
    7.5
    High

    CVE-2022-26975

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.

    Published: 1 Jun 2022
    6.1
    Medium

    CVE-2022-26974

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.

    Published: 1 Jun 2022
    5.3
    Medium

    CVE-2022-26973

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.

    Published: 1 Jun 2022
    6.1
    Medium

    CVE-2022-26972

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.

    Published: 1 Jun 2022
    5.3
    Medium

    CVE-2022-26971

    Last Modified: 21 Nov 2024

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-29875

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable.

    Published: 1 Jun 2022
    6.5
    Medium

    CVE-2022-1285

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

    Published: 1 Jun 2022
    7.8
    High

    CVE-2022-32200

    Last Modified: 21 Nov 2024

    libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.

    Published: 1 Jun 2022
    5.5
    Medium

    CVE-2022-32201

    Last Modified: 21 Nov 2024

    In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp.

    Published: 1 Jun 2022
    5.5
    Medium

    CVE-2022-32202

    Last Modified: 21 Nov 2024

    In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp.

    Published: 1 Jun 2022
    7.2
    High

    CVE-2021-44080

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.

    Published: 1 Jun 2022
    9.8
    Critical

    CVE-2022-30490

    Last Modified: 21 Nov 2024

    Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.

    Published: 1 Jun 2022
    0
    Low

    CVE-2022-1970

    Last Modified: 29 May 2024

    The originally reported issue in https://github.com/syedsohaibkarim/OpenRedirect-Keycloak18.0.0 is a known misconfiguration, and recommendation already exists in the Keycloak documentation to mitigate the issue: https://www.keycloak.org/docs/latest/server_admin/index.html#open-redirectors.

    Published: 1 Jun 2022
    7.4
    High

    CVE-2022-2996

    Last Modified: 21 Nov 2024

    A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

    Published: 1 Jun 2022
    5.5
    Medium

    CVE-2022-38791

    Last Modified: 21 Nov 2024

    In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

    Published: 1 Jun 2022
    5.5
    Medium

    CVE-2022-1852

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.

    Published: 1 Jun 2022
    4.6
    Medium

    CVE-2022-20132

    Last Modified: 21 Nov 2024

    In lg_probe and related functions of hid-lg.c and other USB HID files, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure if a malicious USB HID device were plugged in, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-188677105References: Upstream kernel

    Published: 1 Jun 2022
    4.9
    Medium

    CVE-2021-27778

    Last Modified: 21 Nov 2024

    HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2021-44095

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2021-44096

    Last Modified: 21 Nov 2024

    EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2021-44097

    Last Modified: 21 Nov 2024

    EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.

    Published: 31 May 2022