CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-33642

    Last Modified: 2 Apr 2025

    When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.

    Published: 28 May 2022
    7.8
    High

    CVE-2022-31782

    Last Modified: 21 Nov 2024

    ftbench.c in FreeType Demo Programs through 2.12.1 has a heap-based buffer overflow.

    Published: 27 May 2022
    4.3
    Medium

    CVE-2022-29627

    Last Modified: 21 Nov 2024

    An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.

    Published: 27 May 2022
    5.4
    Medium

    CVE-2022-29628

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-29694

    Last Modified: 21 Nov 2024

    Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-29695

    Last Modified: 21 Nov 2024

    Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-29693

    Last Modified: 21 Nov 2024

    Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c.

    Published: 27 May 2022
    7.8
    High

    CVE-2022-29692

    Last Modified: 21 Nov 2024

    Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-24581

    Last Modified: 21 Nov 2024

    ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-24241

    Last Modified: 21 Nov 2024

    ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-24240

    Last Modified: 21 Nov 2024

    ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-24239

    Last Modified: 21 Nov 2024

    ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-24238

    Last Modified: 21 Nov 2024

    ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp.

    Published: 27 May 2022
    7.5
    High

    CVE-2022-30496

    Last Modified: 21 Nov 2024

    SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-30349

    Last Modified: 21 Nov 2024

    siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-29598

    Last Modified: 21 Nov 2024

    Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-25237

    Last Modified: 21 Nov 2024

    Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-30513

    Last Modified: 21 Nov 2024

    School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125

    Published: 27 May 2022
    6.6
    Medium

    CVE-2021-27781

    Last Modified: 21 Nov 2024

    The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.

    Published: 27 May 2022
    5.3
    Medium

    CVE-2021-27780

    Last Modified: 21 Nov 2024

    The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30511

    Last Modified: 21 Nov 2024

    School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-30514

    Last Modified: 21 Nov 2024

    School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30324

    Last Modified: 21 Nov 2024

    HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

    Published: 27 May 2022
    4.3
    Medium

    CVE-2022-20807

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 27 May 2022
    4.3
    Medium

    CVE-2022-20806

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 27 May 2022
    5.4
    Medium

    CVE-2022-20802

    Last Modified: 21 Nov 2024

    A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input that is processed by the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system. A successful exploit could allow the attacker to execute arbitrary code in the context of the interface or access sensitive, browser-based information. To successfully exploit this vulnerability, an attacker would need valid agent credentials.

    Published: 27 May 2022
    5.5
    Medium

    CVE-2022-20797

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system. This vulnerability is due to insufficient user input validation by the web-based management interface of the affected software. An attacker could exploit this vulnerability by injecting arbitrary commands in the web-based management interface. A successful exploit could allow the attacker to make configuration changes on the affected device or cause certain services to restart unexpectedly.

    Published: 27 May 2022
    4.8
    Medium

    CVE-2022-20765

    Last Modified: 21 Nov 2024

    A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to affected web applications. A successful exploit could allow the attacker to rewrite web page content, access sensitive information stored in the applications, and alter data by submitting forms.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20674

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20673

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20672

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20671

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20670

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20669

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20668

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20667

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-20666

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30512

    Last Modified: 21 Nov 2024

    School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30352

    Last Modified: 21 Nov 2024

    phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30423

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.

    Published: 27 May 2022
    9.8
    Critical

    CVE-2022-30506

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.

    Published: 27 May 2022
    5.5
    Medium

    CVE-2022-30503

    Last Modified: 21 Nov 2024

    Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_set_number at src/njs_value.h.

    Published: 27 May 2022
    5.5
    Medium

    CVE-2022-29780

    Last Modified: 21 Nov 2024

    Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_prototype_sort at src/njs_array.c.

    Published: 27 May 2022
    5.5
    Medium

    CVE-2022-29779

    Last Modified: 21 Nov 2024

    Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.

    Published: 27 May 2022
    8.8
    High

    CVE-2022-30425

    Last Modified: 21 Nov 2024

    Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. This vulnerability is exploited via a crafted POST request.

    Published: 27 May 2022
    8.8
    High

    CVE-2022-29735

    Last Modified: 21 Nov 2024

    Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.

    Published: 27 May 2022
    5.4
    Medium

    CVE-2022-29734

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

    Published: 27 May 2022
    5.9
    Medium

    CVE-2022-29733

    Last Modified: 21 Nov 2024

    Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack.

    Published: 27 May 2022
    6.1
    Medium

    CVE-2022-29732

    Last Modified: 21 Nov 2024

    Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 27 May 2022
    4.3
    Medium

    CVE-2022-29731

    Last Modified: 21 Nov 2024

    An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.

    Published: 27 May 2022