CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-42859

    Last Modified: 21 Nov 2024

    A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release

    Published: 26 May 2022
    6.5
    Medium

    CVE-2021-42692

    Last Modified: 21 Nov 2024

    There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS.

    Published: 26 May 2022
    9.8
    Critical

    CVE-2022-1664

    Last Modified: 21 Nov 2024

    Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.

    Published: 26 May 2022
    5.3
    Medium

    CVE-2021-34360

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later

    Published: 26 May 2022
    7.8
    High

    CVE-2022-30789

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-30788

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-30786

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-30784

    Last Modified: 2 Dec 2025

    A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-1886

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 26 May 2022
    6.7
    Medium

    CVE-2022-30785

    Last Modified: 21 Nov 2024

    A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

    Published: 26 May 2022
    6.7
    Medium

    CVE-2022-30787

    Last Modified: 21 Nov 2024

    An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26702

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    7.8
    High

    CVE-2022-26744

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

    Published: 26 May 2022
    6.7
    Medium

    CVE-2022-30783

    Last Modified: 21 Nov 2024

    An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.

    Published: 26 May 2022
    7.5
    High

    CVE-2022-31004

    Last Modified: 22 Apr 2025

    CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The affected method writes the generated randomKey to disk if the environment is not development. If this method were called in production, it is possible that it would write the plaintext key to disk. A patch is not available as of time of publication but is anticipated as a "hot fix" for version 1.1.1 and for the 2.x branch.

    Published: 25 May 2022
    8.7
    High

    CVE-2022-30999

    Last Modified: 22 Apr 2025

    FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary Javascript code decided by an attacker. This Javascript code could include the execution of HTTP web requests to Flarum, or any other web service. This could allow data to be leaked by an authenticated Flarum user, or, possibly, for data to be modified maliciously. This issue has been patched with v1.2.3, which now sanitizes uploaded SVG files. As a workaround, remove the ability for users to upload SVG files through FoF Upload.

    Published: 25 May 2022
    6.5
    Medium

    CVE-2022-29256

    Last Modified: 23 Apr 2025

    sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of the `PKG_CONFIG_PATH` environment variable in a build environment then they might be able to use this to inject an arbitrary command at `npm install` time. This is not part of any runtime code, does not affect Windows users at all, and is unlikely to affect anyone that already cares about the security of their build environment. This problem is fixed in version 0.30.5.

    Published: 25 May 2022
    7.4
    High

    CVE-2022-29251

    Last Modified: 23 Apr 2025

    XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the `FlamingoThemesCode.WebHomeSheet` wiki page related to the "newThemeName" form field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page `FlamingoThemesCode.WebHomeSheet` (with wiki editor) according to the suggestion provided in the GitHub Security Advisory.

    Published: 25 May 2022
    7.4
    High

    CVE-2022-29252

    Last Modified: 23 Apr 2025

    XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field. The issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3. The easiest available workaround is to edit the wiki page `WikiManager.JoinWiki` (with wiki editor) according to the suggestion provided in the GitHub Security Advisory.

    Published: 25 May 2022
    2.7
    Low

    CVE-2022-29253

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and a path with ".." in it. The issue is patched in versions 14.0 and 13.10.3. There is no easy workaround for this issue.

    Published: 25 May 2022
    7.5
    High

    CVE-2022-27169

    Last Modified: 15 Apr 2025

    An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to trigger this vulnerability.

    Published: 25 May 2022
    9.4
    Critical

    CVE-2022-26833

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.

    Published: 25 May 2022
    7.5
    High

    CVE-2022-26303

    Last Modified: 15 Apr 2025

    An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of an OAS user account. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 25 May 2022
    9.1
    Critical

    CVE-2022-26082

    Last Modified: 15 Apr 2025

    A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 25 May 2022
    7.5
    High

    CVE-2022-26077

    Last Modified: 15 Apr 2025

    A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of Open Automation Software OAS Platform V16.00.0112. A targeted network sniffing attack can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

    Published: 25 May 2022
    4.9
    Medium

    CVE-2022-26067

    Last Modified: 15 Apr 2025

    An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to arbitrary file read. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 25 May 2022
    7.5
    High

    CVE-2022-26043

    Last Modified: 15 Apr 2025

    An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 25 May 2022
    7.5
    High

    CVE-2022-26026

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to loss of communications. An attacker can send a network request to trigger this vulnerability.

    Published: 25 May 2022
    6.5
    Medium

    CVE-2022-31620

    Last Modified: 21 Nov 2024

    In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded sequential scan.

    Published: 25 May 2022
    6.8
    Medium

    CVE-2022-29402

    Last Modified: 21 Nov 2024

    TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.

    Published: 25 May 2022
    4.7
    Medium

    CVE-2022-29408

    Last Modified: 20 Feb 2025

    Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.

    Published: 25 May 2022
    9.8
    Critical

    CVE-2022-23775

    Last Modified: 21 Nov 2024

    TrueStack Direct Connect 1.4.7 has Incorrect Access Control.

    Published: 25 May 2022
    8.8
    High

    CVE-2022-27305

    Last Modified: 21 Nov 2024

    Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

    Published: 25 May 2022
    8.4
    High

    CVE-2021-44719

    Last Modified: 21 Nov 2024

    Docker Desktop 4.3.0 has Incorrect Access Control.

    Published: 25 May 2022
    7.5
    High

    CVE-2022-30427

    Last Modified: 21 Nov 2024

    In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.

    Published: 25 May 2022
    7.5
    High

    CVE-2022-30428

    Last Modified: 21 Nov 2024

    In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.

    Published: 25 May 2022
    6.8
    Medium

    CVE-2021-27783

    Last Modified: 21 Nov 2024

    User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.

    Published: 25 May 2022
    9.1
    Critical

    CVE-2021-27779

    Last Modified: 21 Nov 2024

    VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

    Published: 25 May 2022
    4.3
    Medium

    CVE-2022-28875

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aemobile component can crash the scanning engine. The exploit can be triggered remotely by an attacker.

    Published: 25 May 2022
    6.7
    Medium

    CVE-2022-26691

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.

    Published: 25 May 2022
    7.2
    High

    CVE-2022-22127

    Last Modified: 21 Nov 2024

    Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing users. The vulnerability allows a malicious site administrator to change passwords for users in different sites hosted on the same Tableau Server, resulting in the potential for unauthorized access to data.Tableau Server versions affected are:2020.4.16, 2021.1.13, 2021.2.10, 2021.3.9, 2021.4.4 and earlierNote: All future releases of Tableau Server will address this security issue. Versions that are no longer supported are not tested and may be vulnerable.

    Published: 25 May 2022
    6.5
    Medium

    CVE-2021-35487

    Last Modified: 21 Nov 2024

    Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.

    Published: 25 May 2022
    8.2
    High

    CVE-2021-32997

    Last Modified: 16 Apr 2025

    The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

    Published: 25 May 2022
    9.3
    Critical

    CVE-2021-32989

    Last Modified: 16 Apr 2025

    When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.

    Published: 25 May 2022
    3.7
    Low

    CVE-2021-32966

    Last Modified: 16 Apr 2025

    Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP referrals, which may allow an attacker to remotely read LDAP system credentials.

    Published: 25 May 2022
    4.8
    Medium

    CVE-2022-29380

    Last Modified: 21 Nov 2024

    Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.

    Published: 25 May 2022
    9.8
    Critical

    CVE-2022-29379

    Last Modified: 21 Nov 2024

    Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release

    Published: 25 May 2022
    7.2
    High

    CVE-2022-29651

    Last Modified: 30 Mar 2026

    An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 25 May 2022
    9.8
    Critical

    CVE-2022-29650

    Last Modified: 30 Mar 2026

    Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

    Published: 25 May 2022
    5.5
    Medium

    CVE-2021-44974

    Last Modified: 21 Nov 2024

    radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol parser.

    Published: 25 May 2022