CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2022-1261

    Last Modified: 16 Apr 2025

    Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system processes with system-level privileges.

    Published: 26 May 2022
    8.8
    High

    CVE-2021-33014

    Last Modified: 16 Apr 2025

    An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30495

    Last Modified: 21 Nov 2024

    In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)

    Published: 26 May 2022
    9.8
    Critical

    CVE-2021-33016

    Last Modified: 16 Apr 2025

    An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30493

    Last Modified: 21 Nov 2024

    In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).

    Published: 26 May 2022
    5.4
    Medium

    CVE-2022-30494

    Last Modified: 21 Nov 2024

    In oretnom23 Automotive Shop Management System v1.0, the first and last name user fields suffer from a stored XSS Injection Vulnerability allowing remote attackers to gain admin access and view internal IPs.

    Published: 26 May 2022
    9.1
    Critical

    CVE-2022-1899

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30516

    Last Modified: 21 Nov 2024

    In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30500

    Last Modified: 21 Nov 2024

    Jfinal cms 5.1.0 is vulnerable to SQL Injection.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30477

    Last Modified: 21 Nov 2024

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetClientState request.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30476

    Last Modified: 21 Nov 2024

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.

    Published: 26 May 2022
    7.5
    High

    CVE-2022-30475

    Last Modified: 21 Nov 2024

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/WifiExtraSet request.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30474

    Last Modified: 21 Nov 2024

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-30472

    Last Modified: 21 Nov 2024

    Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat

    Published: 26 May 2022
    5.3
    Medium

    CVE-2022-29091

    Last Modified: 21 Nov 2024

    Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior to 5.2.0.0.5.173 contain a Reflected Cross-Site Scripting Vulnerability in Unisphere GUI. An Unauthenticated Remote Attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

    Published: 26 May 2022
    3.7
    Low

    CVE-2022-29082

    Last Modified: 21 Nov 2024

    Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0.x, 19.4.x, 19.4.0.x, 19.5.x,19.5.0.x, 19.6 and 19.6.0.1 and 19.6.0.2 contain an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port 5671 which could allow remote attackers to spoof certificates.

    Published: 26 May 2022
    6.8
    Medium

    CVE-2022-26865

    Last Modified: 21 Nov 2024

    Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator.

    Published: 26 May 2022
    9
    Critical

    CVE-2022-26857

    Last Modified: 21 Nov 2024

    Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.

    Published: 26 May 2022
    9.6
    Critical

    CVE-2022-24422

    Last Modified: 21 Nov 2024

    Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.

    Published: 26 May 2022
    7.5
    High

    CVE-2022-24418

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

    Published: 26 May 2022
    7.5
    High

    CVE-2022-24417

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

    Published: 26 May 2022
    7.6
    High

    CVE-2022-24414

    Last Modified: 21 Nov 2024

    Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. Tokens should not be used in request URL to avoid such attacks.

    Published: 26 May 2022
    7.5
    High

    CVE-2022-30473

    Last Modified: 21 Nov 2024

    Tenda AC Series Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function form_fast_setting_wifi_set

    Published: 26 May 2022
    6.5
    Medium

    CVE-2022-20821

    Last Modified: 28 Oct 2025

    A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system.

    Published: 26 May 2022
    4.3
    Medium

    CVE-2022-20809

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29689

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29688

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29687

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29686

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.

    Published: 26 May 2022
    8.8
    High

    CVE-2022-29685

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29684

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29682

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29683

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29680

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29681

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29676

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29670

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del.

    Published: 26 May 2022
    8.8
    High

    CVE-2022-29669

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.

    Published: 26 May 2022
    8.8
    High

    CVE-2022-29667

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29666

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29665

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.

    Published: 26 May 2022
    8.8
    High

    CVE-2022-29664

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29663

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29662

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.

    Published: 26 May 2022
    7.2
    High

    CVE-2022-29661

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-29660

    Last Modified: 21 Nov 2024

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.

    Published: 26 May 2022
    7.5
    High

    CVE-2022-29721

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

    Published: 26 May 2022
    7.5
    High

    CVE-2022-29720

    Last Modified: 21 Nov 2024

    74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.

    Published: 26 May 2022
    8.8
    High

    CVE-2021-40317

    Last Modified: 21 Nov 2024

    Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.

    Published: 26 May 2022
    7.5
    High

    CVE-2021-42860

    Last Modified: 21 Nov 2024

    A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification

    Published: 26 May 2022