CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2022-0734

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.

    Published: 24 May 2022
    8.1
    High

    CVE-2022-29305

    Last Modified: 21 Nov 2024

    imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.

    Published: 24 May 2022
    7.5
    High

    CVE-2022-29377

    Last Modified: 21 Nov 2024

    Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.

    Published: 24 May 2022
    7.5
    High

    CVE-2022-23712

    Last Modified: 21 Nov 2024

    A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

    Published: 24 May 2022
    9.8
    Critical

    CVE-2022-26945

    Last Modified: 21 Nov 2024

    go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.

    Published: 24 May 2022
    8.8
    High

    CVE-2022-29221

    Last Modified: 23 Apr 2025

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully trust template authors should upgrade to versions 3.1.45 or 4.1.1 to receive a patch for this issue. There are currently no known workarounds.

    Published: 24 May 2022
    8.6
    High

    CVE-2022-30321

    Last Modified: 21 Nov 2024

    go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.

    Published: 24 May 2022
    8.6
    High

    CVE-2022-30323

    Last Modified: 21 Nov 2024

    go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.

    Published: 24 May 2022
    7.8
    High

    CVE-2022-1786

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system.

    Published: 24 May 2022
    6.1
    Medium

    CVE-2022-26531

    Last Modified: 21 Nov 2024

    Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to cause a buffer overflow or a system crash via a crafted payload.

    Published: 24 May 2022
    8.6
    High

    CVE-2022-30322

    Last Modified: 21 Nov 2024

    go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.

    Published: 24 May 2022
    8.8
    High

    CVE-2022-29002

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.

    Published: 23 May 2022
    5.4
    Medium

    CVE-2022-30015

    Last Modified: 21 Nov 2024

    In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.

    Published: 23 May 2022
    8.8
    High

    CVE-2022-29376

    Last Modified: 15 Aug 2025

    Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.

    Published: 23 May 2022
    8.8
    High

    CVE-2022-28999

    Last Modified: 21 Nov 2024

    Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe.

    Published: 23 May 2022
    7.5
    High

    CVE-2022-31487

    Last Modified: 21 Nov 2024

    Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.

    Published: 23 May 2022
    7.5
    High

    CVE-2022-31488

    Last Modified: 21 Nov 2024

    Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.

    Published: 23 May 2022
    7.5
    High

    CVE-2022-31489

    Last Modified: 21 Nov 2024

    Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.

    Published: 23 May 2022
    5.5
    Medium

    CVE-2021-32958

    Last Modified: 16 Apr 2025

    Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.

    Published: 23 May 2022
    7.4
    High

    CVE-2022-1467

    Last Modified: 16 Apr 2025

    Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.

    Published: 23 May 2022
    9.4
    Critical

    CVE-2021-32941

    Last Modified: 16 Apr 2025

    Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

    Published: 23 May 2022
    8.8
    High

    CVE-2021-32935

    Last Modified: 16 Apr 2025

    The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.

    Published: 23 May 2022
    7.9
    High

    CVE-2022-31466

    Last Modified: 21 Nov 2024

    Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as malicious and when the action of quarantining or cleaning is performed, and using the time to replace the malicious file by a symlink.

    Published: 23 May 2022
    7.9
    High

    CVE-2022-31467

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not verifying the signature of the DLLs it tries to load.

    Published: 23 May 2022
    5.4
    Medium

    CVE-2021-42233

    Last Modified: 21 Nov 2024

    The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.

    Published: 23 May 2022
    8.8
    High

    CVE-2022-28944

    Last Modified: 21 Nov 2024

    Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows 5.8.22 and Network Software Scanner for Windows 2.0.8 and UnLock IT for Windows 6.1.1. The impact is: execute arbitrary code (remote). The component is: Updater. The attack vector is: To exploit this vulnerability, a user must trigger an update of an affected installation of EMCO Software. ¶¶ Multiple products from EMCO Software are affected by a remote code execution vulnerability during the update process.

    Published: 23 May 2022
    8.8
    High

    CVE-2022-30016

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.

    Published: 23 May 2022
    5.4
    Medium

    CVE-2022-30017

    Last Modified: 21 Nov 2024

    Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.

    Published: 23 May 2022
    9.8
    Critical

    CVE-2022-28932

    Last Modified: 21 Nov 2024

    D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

    Published: 23 May 2022
    8.8
    High

    CVE-2022-30014

    Last Modified: 21 Nov 2024

    Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.

    Published: 23 May 2022
    6.1
    Medium

    CVE-2022-29004

    Last Modified: 21 Nov 2024

    Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

    Published: 23 May 2022
    7.7
    High

    CVE-2021-41714

    Last Modified: 21 Nov 2024

    In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.

    Published: 23 May 2022
    6.1
    Medium

    CVE-2022-29005

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

    Published: 23 May 2022
    8.1
    High

    CVE-2022-28998

    Last Modified: 21 Nov 2024

    Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.

    Published: 23 May 2022
    7.5
    High

    CVE-2022-28997

    Last Modified: 21 Nov 2024

    CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.

    Published: 23 May 2022
    5.4
    Medium

    CVE-2022-1811

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

    Published: 23 May 2022
    5.4
    Medium

    CVE-2022-0900

    Last Modified: 20 May 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NetDataSoft DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from unspecified before v.4.6.2.0.

    Published: 23 May 2022
    3.5
    Low

    CVE-2022-1817

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

    Published: 23 May 2022
    3.5
    Low

    CVE-2022-1816

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

    Published: 23 May 2022
    5.4
    Medium

    CVE-2022-1825

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.

    Published: 23 May 2022
    8.8
    High

    CVE-2021-42586

    Last Modified: 21 Nov 2024

    A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

    Published: 23 May 2022
    8.8
    High

    CVE-2021-42585

    Last Modified: 21 Nov 2024

    A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

    Published: 23 May 2022
    4.3
    Medium

    CVE-2022-28874

    Last Modified: 21 Nov 2024

    Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.

    Published: 23 May 2022
    4.8
    Medium

    CVE-2022-1558

    Last Modified: 21 Nov 2024

    The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

    Published: 23 May 2022
    6.1
    Medium

    CVE-2022-1547

    Last Modified: 21 Nov 2024

    The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 23 May 2022
    4.8
    Medium

    CVE-2022-1320

    Last Modified: 21 Nov 2024

    The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 23 May 2022
    4.8
    Medium

    CVE-2022-1298

    Last Modified: 21 Nov 2024

    The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 23 May 2022
    6.1
    Medium

    CVE-2022-1268

    Last Modified: 21 Nov 2024

    The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected cross-Site Scripting

    Published: 23 May 2022
    6.1
    Medium

    CVE-2022-1221

    Last Modified: 21 Nov 2024

    The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

    Published: 23 May 2022
    6.1
    Medium

    CVE-2022-1218

    Last Modified: 21 Nov 2024

    The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 23 May 2022