CVE Feed

    Dashboard / CVE

    3.7
    Low

    CVE-2021-4230

    Last Modified: 15 Apr 2025

    A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. It is recommended to the change the configuration settings.

    Published: 24 May 2022
    5
    Medium

    CVE-2021-4229

    Last Modified: 15 Apr 2025

    A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 24 May 2022
    8.1
    High

    CVE-2014-125001

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.

    Published: 24 May 2022
    6.5
    Medium

    CVE-2013-10004

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Password Handler. Incorrect implementation of a hashing function leads to predictable authentication possibilities. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 24 May 2022
    6.5
    Medium

    CVE-2013-10003

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. This affects the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the database handler. The manipulation leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 24 May 2022
    6.5
    Medium

    CVE-2013-10002

    Last Modified: 15 Apr 2025

    A vulnerability was found in Telecommunication Software SAMwin Contact Center Suite 5.1. It has been rated as critical. Affected by this issue is the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the credential handler. Authentication is possible with hard-coded credentials. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 24 May 2022
    7.5
    High

    CVE-2022-29249

    Last Modified: 23 Apr 2025

    JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of security are required. This issue ONLY affects v1.6 and does not affect anything pre-1.6. The vulnerability has been patched in release 1.7. Currently, there is no way to fix the issue without upgrading.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2022-29246

    Last Modified: 27 Oct 2025

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker to bypass security features or execute arbitrary code. The implementation of `ux_device_class_dfu_control_request` function does not assure that a buffer overflow will not occur during handling of the DFU UPLOAD command. When an attacker issues the `UX_SLAVE_CLASS_DFU_COMMAND_UPLOAD` control transfer request with `wLenght` larger than the buffer size (`UX_SLAVE_REQUEST_CONTROL_MAX_LENGTH`, 256 bytes), depending on the actual implementation of `dfu -> ux_slave_class_dfu_read`, a buffer overflow may occur. In example `ux_slave_class_dfu_read` may read 4096 bytes (or more up to 65k) to a 256 byte buffer ultimately resulting in an overflow. Furthermore in case an attacker has some control over the read flash memory, this may result in execution of arbitrary code and platform compromise. A fix for this issue has been included in USBX release 6.1.11. As a workaround, align request and buffer size to assure that buffer boundaries are respected.

    Published: 24 May 2022
    5.9
    Medium

    CVE-2022-29242

    Last Modified: 23 Apr 2025

    GOST engine is a reference implementation of the Russian GOST crypto algorithms for OpenSSL. TLS clients using GOST engine when ciphersuite `TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC` is agreed and the server uses 512 bit GOST secret keys are vulnerable to buffer overflow. GOST engine version 3.0.1 contains a patch for this issue. Disabling ciphersuite `TLS_GOSTR341112_256_WITH_KUZNYECHIK_CTR_OMAC` is a possible workaround.

    Published: 24 May 2022
    7.5
    High

    CVE-2022-31261

    Last Modified: 21 Nov 2024

    An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A remote attacker can send a request crafted with an XXE payload to invoke a malicious DTD hosted on a system that they control. This results in reading local files that the application has access to.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-29237

    Last Modified: 23 Apr 2025

    Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass along URLs for files belonging to organizations other than the user's own, which Opencast would then import into the current organization, bypassing organizational barriers. Attackers must have full access to Opencast's ingest REST interface, and also know internal links to resources in another organization of the same Opencast cluster. Users who do not run a multi-tenant cluster are not affected by this issue. This issue is fixed in Opencast 10.14 and 11.7.

    Published: 24 May 2022
    5.5
    Medium

    CVE-2021-44975

    Last Modified: 21 Nov 2024

    radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-22306

    Last Modified: 21 Nov 2024

    An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication between the FortiGate and some peers such as private SDNs and external cloud platforms.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2021-45914

    Last Modified: 21 Nov 2024

    In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2021-45915

    Last Modified: 21 Nov 2024

    In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.

    Published: 24 May 2022
    7.5
    High

    CVE-2022-29223

    Last Modified: 27 Oct 2025

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MAX_TT` which defaults to 8. For a `bNbPorts` value of 255, the implementation of `ux_host_class_hub_descriptor_get` function will modify the contents of `hub` -> `ux_host_class_hub_device` -> `ux_device_hub_tt` array violating the end boundary by 255 - `UX_MAX_TT` items. The USB host stack needs to validate the number of ports reported by the hub, and if the value is larger than UX_MAX_TT, USB stack needs to reject the request. This fix has been included in USBX release 6.1.10.

    Published: 24 May 2022
    5.7
    Medium

    CVE-2022-29567

    Last Modified: 21 Nov 2024

    The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.

    Published: 24 May 2022
    —
    Unknown

    CVE-2022-30457

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 24 May 2022
    7.5
    High

    CVE-2022-29219

    Last Modified: 23 Apr 2025

    Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64` values as native javascript `number`s, there is an issue when those variables with large (greater than 2^53) `uint64` values are included on chain. In those cases, Lodestar may view valid_`AttesterSlashing` or `ProposerSlashing` as invalid, due to rounding errors in large `number` values. This causes a consensus split, where Lodestar nodes are forked away from the main network. Similarly, Lodestar may consider invalid `ProposerSlashing` as valid, thus including in proposed blocks that will be considered invalid by the network. Version 0.36.0 contains a fix for this issue. As a workaround, use `BigInt` to represent `Slot` and `Epoch` values in `AttesterSlashing` and `ProposerSlashing` objects. `BigInt` is too slow to be used in all `Slot` and `Epoch` cases, so one may carefully use `BigInt` just where necessary for consensus.

    Published: 24 May 2022
    6.1
    Medium

    CVE-2022-30839

    Last Modified: 21 Nov 2024

    Room-rent-portal-site v1.0 is vulnerable to Cross Site Scripting (XSS) via /rrps/classes/Master.php?f=save_category, vehicle_name.

    Published: 24 May 2022
    8.8
    High

    CVE-2022-30843

    Last Modified: 21 Nov 2024

    Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2022-30838

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-30842

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=save, firstname.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-30837

    Last Modified: 24 Feb 2025

    Toll-tax-management-system v1.0 is vulnerable to Cross Site Scripting (XSS) via /ttms/classes/Master.php?f=save_recipient, vehicle_name.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2022-30461

    Last Modified: 21 Nov 2024

    Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-30462

    Last Modified: 21 Nov 2024

    Water-billing-management-system v1.0 is affected by: Cross Site Scripting (XSS) via /wbms/classes/Users.php?f=save, firstname.

    Published: 24 May 2022
    8.8
    High

    CVE-2022-30459

    Last Modified: 21 Nov 2024

    ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-30464

    Last Modified: 21 Nov 2024

    ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to Cross Site Scripting (XSS) via /simple_chat_bot/classes/Master.php?f=save_response.

    Published: 24 May 2022
    8.8
    High

    CVE-2022-30463

    Last Modified: 21 Nov 2024

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-30458

    Last Modified: 21 Nov 2024

    Automotive Shop Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /asms/classes/Master.php?f=save_product, name.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-30460

    Last Modified: 21 Nov 2024

    Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstname.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2021-42656

    Last Modified: 21 Nov 2024

    SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2022-30455

    Last Modified: 21 Nov 2024

    Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-30456

    Last Modified: 21 Nov 2024

    Badminton Center Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /bcms/classes/Master.php?f=save_court_rental.

    Published: 24 May 2022
    8.8
    High

    CVE-2021-42655

    Last Modified: 21 Nov 2024

    SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2022-30454

    Last Modified: 21 Nov 2024

    Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2021-42654

    Last Modified: 21 Nov 2024

    SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

    Published: 24 May 2022
    8.1
    High

    CVE-2022-1850

    Last Modified: 21 Nov 2024

    Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.

    Published: 24 May 2022
    5.4
    Medium

    CVE-2022-1849

    Last Modified: 21 Nov 2024

    Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.

    Published: 24 May 2022
    6.5
    Medium

    CVE-2021-42659

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs.

    Published: 24 May 2022
    5.3
    Medium

    CVE-2022-1848

    Last Modified: 21 Nov 2024

    Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.

    Published: 24 May 2022
    2.4
    Low

    CVE-2022-1840

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This issue affects register.php?link=registerand. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but demands authentication. Exploit details have been disclosed to the public.

    Published: 24 May 2022
    6.3
    Medium

    CVE-2022-1839

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affects the file login.php. The manipulation of the argument email with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(2)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. The attack can be initiated remotely but it requires authentication. Exploit details have been disclosed to the public.

    Published: 24 May 2022
    4.7
    Medium

    CVE-2022-1838

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

    Published: 24 May 2022
    4.7
    Medium

    CVE-2022-1837

    Last Modified: 15 Apr 2025

    A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.

    Published: 24 May 2022
    2.4
    Low

    CVE-2022-1819

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?page=students of the Student Roll module. The manipulation with the input <script>alert(1)</script> leads to authenticated cross site scripting. Exploit details have been disclosed to the public.

    Published: 24 May 2022
    7.8
    High

    CVE-2022-26532

    Last Modified: 21 Nov 2024

    A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to execute arbitrary OS commands by including crafted arguments to the CLI command.

    Published: 24 May 2022
    5.3
    Medium

    CVE-2022-31263

    Last Modified: 21 Nov 2024

    app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.

    Published: 24 May 2022
    6.5
    Medium

    CVE-2022-0910

    Last Modified: 21 Nov 2024

    A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through 5.21, that could allow an authenticated attacker to bypass the second authentication phase to connect the IPsec VPN server even though the two-factor authentication (2FA) was enabled.

    Published: 24 May 2022
    7.5
    High

    CVE-2022-29309

    Last Modified: 22 Apr 2025

    mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.

    Published: 24 May 2022