CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-44098

    Last Modified: 21 Nov 2024

    EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

    Published: 31 May 2022
    5.5
    Medium

    CVE-2021-43512

    Last Modified: 21 Nov 2024

    An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-28945

    Last Modified: 21 Nov 2024

    An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2021-42872

    Last Modified: 21 Nov 2024

    TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-31015

    Last Modified: 22 Apr 2025

    Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate early due to a thread closing a socket while the main thread is about to call select(). This will lead to the main thread raising an exception that is not handled and then causing the entire application to be killed. This issue has been fixed in Waitress 2.1.2 by no longer allowing the WSGI thread to close the socket. Instead, that is always delegated to the main thread. There is no work-around for this issue. However, users using waitress behind a reverse proxy server are less likely to have issues if the reverse proxy always reads the full response.

    Published: 31 May 2022
    7.8
    High

    CVE-2021-42204

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution.

    Published: 31 May 2022
    9.1
    Critical

    CVE-2022-31013

    Last Modified: 23 Apr 2025

    Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an async function, as the code is not using `await` to wait for the verification result. Every time the function responds back with success, along with an unhandled exception if the token is invalid. A patch is available in version 2.6.0.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-1947

    Last Modified: 21 Nov 2024

    Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-1808

    Last Modified: 21 Nov 2024

    Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.

    Published: 31 May 2022
    4.6
    Medium

    CVE-2022-1893

    Last Modified: 21 Nov 2024

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.

    Published: 31 May 2022
    6.1
    Medium

    CVE-2022-29653

    Last Modified: 21 Nov 2024

    OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.

    Published: 31 May 2022
    5.4
    Medium

    CVE-2022-29648

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-29647

    Last Modified: 21 Nov 2024

    An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

    Published: 31 May 2022
    8.8
    High

    CVE-2021-32546

    Last Modified: 21 Nov 2024

    Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (registered user) can overwrite the Git configuration in his repository. This leads to Remote Command Execution, because that configuration can contain an option such as sshCommand, which is executed when a master branch is a remote branch (using an ssh:// URI). The remote branch can also be configured by editing the Git configuration file. One can create a new file in a new repository, using the GUI, with "\" as its name, and then rename this file to .git/config with the custom configuration content (and then save it).

    Published: 31 May 2022
    8.8
    High

    CVE-2022-29624

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30478

    Last Modified: 21 Nov 2024

    Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.

    Published: 31 May 2022
    —
    Unknown

    CVE-2022-32191

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 31 May 2022
    4.8
    Medium

    CVE-2022-30482

    Last Modified: 21 Nov 2024

    Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.php via the ctg_name parameters.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30481

    Last Modified: 21 Nov 2024

    Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters.

    Published: 31 May 2022
    6.1
    Medium

    CVE-2022-29540

    Last Modified: 21 Nov 2024

    resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that reflects user input without sanitization. This exists on numerous application endpoints,

    Published: 31 May 2022
    4.9
    Medium

    CVE-2021-33504

    Last Modified: 21 Nov 2024

    Couchbase Server before 7.1.0 has Incorrect Access Control.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-28605

    Last Modified: 21 Nov 2024

    Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory

    Published: 31 May 2022
    7.8
    High

    CVE-2022-24701

    Last Modified: 21 Nov 2024

    An issue was discovered in WinAPRS 2.9.0. A buffer overflow in national.txt processing allows a local attacker to cause a denial of service or possibly achieve code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 31 May 2022
    7.5
    High

    CVE-2022-24700

    Last Modified: 21 Nov 2024

    An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a remote attacker to cause a denial of service (daemon crash) via a malicious AX.25 packet over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-24702

    Last Modified: 21 Nov 2024

    An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 31 May 2022
    7.5
    High

    CVE-2022-1661

    Last Modified: 16 Apr 2025

    The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.

    Published: 31 May 2022
    7.5
    High

    CVE-2022-31005

    Last Modified: 22 Apr 2025

    Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable FileMiddleware and serve via a Content Delivery Network.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-1660

    Last Modified: 16 Apr 2025

    The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.

    Published: 31 May 2022
    4.3
    Medium

    CVE-2021-36890

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress.

    Published: 31 May 2022
    7.8
    High

    CVE-2022-31011

    Last Modified: 23 Apr 2025

    TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or unauthorized access. Only users using TiDB 5.3.0 are affected by this vulnerability. TiDB version 5.3.1 contains a patch for this issue. Other mitigation strategies include turning off Security Enhanced Mode (SEM), disabling local login for non-root accounts, and ensuring that the same IP cannot be logged in as root and normal user at the same time.

    Published: 31 May 2022
    4.9
    Medium

    CVE-2022-31007

    Last Modified: 23 Apr 2025

    eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the application. The impact is not deemed as high, as it requires the attacker to have access to an administrator account. Regular user accounts cannot exploit this to gain admin rights. A workaround for one if the issues is removing the ability of administrators to create accounts.

    Published: 31 May 2022
    4.8
    Medium

    CVE-2021-36866

    Last Modified: 20 Feb 2025

    Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables plugin <= 3.1.2 at WordPress.

    Published: 31 May 2022
    6.8
    Medium

    CVE-2022-1797

    Last Modified: 16 Apr 2025

    A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online.

    Published: 31 May 2022
    7.8
    High

    CVE-2021-42203

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.

    Published: 31 May 2022
    5.5
    Medium

    CVE-2021-42202

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter() located in swffilter.c. It allows an attacker to cause Denial of Service.

    Published: 31 May 2022
    7.8
    High

    CVE-2021-42201

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2021-40186

    Last Modified: 21 Nov 2024

    The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common scenario, the attacker exploits SSRF vulnerabilities to attack systems behind the firewall and access sensitive information from Cloud Provider metadata services.

    Published: 31 May 2022
    —
    Unknown

    CVE-2022-32150

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 31 May 2022
    7.8
    High

    CVE-2022-29483

    Last Modified: 21 Nov 2024

    Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

    Published: 31 May 2022
    6.1
    Medium

    CVE-2022-28702

    Last Modified: 21 Nov 2024

    Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-30819

    Last Modified: 21 Nov 2024

    In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-30820

    Last Modified: 21 Nov 2024

    In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-30821

    Last Modified: 21 Nov 2024

    In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.

    Published: 31 May 2022
    5.5
    Medium

    CVE-2021-42200

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located in swfdump.c. It allows an attacker to cause Denial of Service.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-30822

    Last Modified: 21 Nov 2024

    In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30823

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30825

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30826

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30827

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30828

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php.

    Published: 31 May 2022