CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-42199

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30829

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30830

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\feature_edit.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30831

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via Wedding-Management/wedding_details.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30832

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=.

    Published: 31 May 2022
    5.5
    Medium

    CVE-2021-42198

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause Denial of Service.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30833

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_edit.php?booking=31&user_id=.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30818

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30834

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id=

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30835

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30836

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php.

    Published: 31 May 2022
    —
    Unknown

    CVE-2022-32147

    Last Modified: 2 Jul 2024

    reserved but not needed

    Published: 31 May 2022
    7.8
    High

    CVE-2021-42197

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution.

    Published: 31 May 2022
    7.4
    High

    CVE-2022-29258

    Last Modified: 23 Apr 2025

    XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.0-milestone-2 and 5.4.4 and prior to versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3, XWiki Platform Filter UI contains a possible cross-site scripting vector in the `Filter.FilterStreamDescriptorForm` wiki page related to pretty much all the form fields printed in the home page of the application. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest workaround is to edit the wiki page `Filter.FilterStreamDescriptorForm` (with wiki editor) according to the instructions in the GitHub Security Advisory.

    Published: 31 May 2022
    5.5
    Medium

    CVE-2021-42196

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function traits_parse() located in abc.c. It allows an attacker to cause Denial of Service.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-29245

    Last Modified: 22 Apr 2025

    SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `System.Random` is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes. When establishing an SSH connection to a remote host, during the X25519 key exchange, the private key is generated with a weak random number generator whose seed can be brute forced. This allows an attacker who is able to eavesdrop on the communications to decrypt them. Version 2020.0.2 contains a patch for this issue. As a workaround, one may disable support for `curve25519-sha256` and `[email protected]` key exchange algorithms.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30817

    Last Modified: 21 Nov 2024

    Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.

    Published: 31 May 2022
    7.8
    High

    CVE-2021-42195

    Last Modified: 21 Nov 2024

    An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() located in swfdump.c. It allows an attacker to cause code Execution.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-30804

    Last Modified: 21 Nov 2024

    elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30808

    Last Modified: 21 Nov 2024

    elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30809

    Last Modified: 21 Nov 2024

    elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30810

    Last Modified: 21 Nov 2024

    elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30813

    Last Modified: 21 Nov 2024

    elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30814

    Last Modified: 21 Nov 2024

    elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.

    Published: 31 May 2022
    4.3
    Medium

    CVE-2022-29243

    Last Modified: 23 Apr 2025

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app passwords with long names. These long names are then loaded into memory on usage, resulting in impacted performance. Versions 22.2.7 and 23.0.4 contain a fix for this issue. There are currently no known workarounds available.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-29220

    Last Modified: 23 Apr 2025

    github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check if the actor is set to `dependabot[bot]` to determine if the PR is a legit PR. Theoretically, an owner of a seemingly valid and legit action in the pipeline can check if the PR is created by dependabot and if their own action has enough permissions to modify the PR in the pipeline. If so, they can modify the PR by adding a second seemingly valid and legit commit to the PR, as they can set arbitrarily the username and email in for commits in git. Because the bot only checks if the actor is valid, it would pass the malicious changes through and merge the PR automatically, without getting noticed by project maintainers. It would probably not be possible to determine where the malicious commit came from, as it would only say `dependabot[bot]` and the corresponding email-address. Version 3.2.0 contains a patch for this issue.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30815

    Last Modified: 21 Nov 2024

    elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30816

    Last Modified: 21 Nov 2024

    elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php.

    Published: 31 May 2022
    6.5
    Medium

    CVE-2022-22361

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0 through 8.6.0.201803, and 8.5.0.0 through 8.5.0.201706 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31329

    Last Modified: 21 Nov 2024

    Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31328

    Last Modified: 21 Nov 2024

    Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31327

    Last Modified: 21 Nov 2024

    Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30799

    Last Modified: 21 Nov 2024

    Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30798

    Last Modified: 21 Nov 2024

    Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.

    Published: 31 May 2022
    —
    Unknown

    CVE-2021-3676

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-30797

    Last Modified: 21 Nov 2024

    Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30795

    Last Modified: 21 Nov 2024

    Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.

    Published: 31 May 2022
    7.2
    High

    CVE-2022-30794

    Last Modified: 21 Nov 2024

    Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31335

    Last Modified: 21 Nov 2024

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31336

    Last Modified: 21 Nov 2024

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31337

    Last Modified: 21 Nov 2024

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-31338

    Last Modified: 21 Nov 2024

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.

    Published: 31 May 2022
    7.5
    High

    CVE-2022-23082

    Last Modified: 21 Nov 2024

    In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.

    Published: 31 May 2022
    8.8
    High

    CVE-2022-29725

    Last Modified: 21 Nov 2024

    An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 31 May 2022
    9.8
    Critical

    CVE-2022-29712

    Last Modified: 21 Nov 2024

    LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.

    Published: 31 May 2022
    6.1
    Medium

    CVE-2022-29711

    Last Modified: 21 Nov 2024

    LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.

    Published: 31 May 2022
    8.6
    High

    CVE-2022-30034

    Last Modified: 21 Nov 2024

    Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.

    Published: 31 May 2022
    7.8
    High

    CVE-2022-31500

    Last Modified: 21 Nov 2024

    In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.

    Published: 31 May 2022
    7.6
    High

    CVE-2021-3555

    Last Modified: 21 Nov 2024

    A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions.

    Published: 31 May 2022
    4.9
    Medium

    CVE-2022-1926

    Last Modified: 21 Nov 2024

    Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.

    Published: 31 May 2022