CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-29194

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.DeleteSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial of service attack. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-28618

    Last Modified: 21 Nov 2024

    A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.

    Published: 20 May 2022
    5.5
    Medium

    CVE-2022-29191

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.GetSessionTensor` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial of service attack. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

    Published: 20 May 2022
    3.4
    Low

    CVE-2022-29432

    Last Modified: 20 Feb 2025

    Multiple Authenticated (administrator or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in TMS-Plugins wpDataTables plugin <= 2.1.27 on WordPress via &data-link-text, &data-link-url, &data, &data-shortcode, &data-star-num vulnerable parameters.

    Published: 20 May 2022
    5.4
    Medium

    CVE-2022-29431

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in KubiQ CPT base plugin <= 5.8 at WordPress allows an attacker to delete the CPT base.

    Published: 20 May 2022
    4.7
    Medium

    CVE-2022-29430

    Last Modified: 20 Feb 2025

    Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter &jpg_quality.

    Published: 20 May 2022
    4.1
    Medium

    CVE-2022-29428

    Last Modified: 20 Feb 2025

    Cross-Site Scripting (XSS) vulnerability in Muneeb's WP Slider Plugin <= 1.4.5 at WordPress.

    Published: 20 May 2022
    5.5
    Medium

    CVE-2022-29192

    Last Modified: 22 Apr 2025

    TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` does not fully validate the input arguments. This results in a `CHECK`-failure which can be used to trigger a denial of service attack. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.

    Published: 20 May 2022
    9.1
    Critical

    CVE-2022-29186

    Last Modified: 23 Apr 2025

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on remote host, those hosts would allow access to anyone with the exposed private credentials. This misconfiguration only impacts Rundeck Docker instances of PagerDuty® Process Automation On Prem (formerly Rundeck) version 4.0 and earlier, not Debian, RPM or .WAR. Additionally, the id_rsa.pub file would have to be copied from the Docker image filesystem contents without overwriting it and used to configure SSH access on a host. A patch on Rundeck's `main` branch has removed the pre-generated SSH key pair, but it does not remove exposed keys that have been configured. To patch, users must run a script on hosts in their environment to search for exposed keys and rotate them. Two workarounds are available: Do not use any pre-existing public key file from the rundeck docker images to allow SSH access by adding it to authorized_keys files and, if you have copied the public key file included in the docker image, remove it from any authorized_keys files.

    Published: 20 May 2022
    6.3
    Medium

    CVE-2022-29434

    Last Modified: 20 Feb 2025

    Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-22972

    Last Modified: 21 Nov 2024

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

    Published: 20 May 2022
    7.8
    High

    CVE-2022-22973

    Last Modified: 21 Nov 2024

    VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

    Published: 20 May 2022
    6.8
    Medium

    CVE-2022-29447

    Last Modified: 20 Feb 2025

    Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.

    Published: 20 May 2022
    4.3
    Medium

    CVE-2022-29427

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress.

    Published: 20 May 2022
    5.4
    Medium

    CVE-2022-29426

    Last Modified: 20 Feb 2025

    Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin <= 1.3.54 at WordPress.

    Published: 20 May 2022
    5.3
    Medium

    CVE-2022-21195

    Last Modified: 21 Nov 2024

    All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash.

    Published: 20 May 2022
    6.8
    Medium

    CVE-2022-29448

    Last Modified: 20 Feb 2025

    Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.

    Published: 20 May 2022
    6.1
    Medium

    CVE-2022-29425

    Last Modified: 20 Feb 2025

    Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress.

    Published: 20 May 2022
    4.8
    Medium

    CVE-2022-29424

    Last Modified: 20 Feb 2025

    Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin <= 9.7.1 at WordPress.

    Published: 20 May 2022
    4.8
    Medium

    CVE-2021-36833

    Last Modified: 20 Jan 2026

    Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.

    Published: 20 May 2022
    4.2
    Medium

    CVE-2022-29185

    Last Modified: 23 Apr 2025

    totp-rs is a Rust library that permits the creation of 2FA authentification tokens per time-based one-time password (TOTP). Prior to version 1.1.0, token comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. Starting with patched version 1.1.0, the library uses constant-time comparison. There are currently no known workarounds.

    Published: 20 May 2022
    8.8
    High

    CVE-2022-29184

    Last Modified: 23 Apr 2025

    GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials or pipeline configuration repositories to get remote code execution capability on the GoCD server via configuring a malicious branch name which abuses Mercurial hooks/aliases to exploit a command injection weakness. An attacker would require access to an account with existing GoCD administration permissions to either create/edit (`hg`-based) configuration repositories; create/edit pipelines and their (`hg`-based) materials; or, where "pipelines-as-code" configuration repositories are used, to commit malicious configuration to such an external repository which will be automatically parsed into a pipeline configuration and (`hg`) material definition by the GoCD server. This issue is fixed in GoCD 22.1.0. As a workaround, users who do not use/rely upon Mercurial materials can uninstall/remove the `hg`/Mercurial binary from the underlying GoCD Server operating system or Docker image.

    Published: 20 May 2022
    4.3
    Medium

    CVE-2022-29183

    Last Modified: 23 Apr 2025

    GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting via abuse of the pipeline comparison function's error handling to render arbitrary HTML into the returned page. This could allow an attacker to trick a victim into executing code which would allow the attacker to operate on, or gain control over the same resources as the victim had access to. This issue is fixed in GoCD 21.4.0. As a workaround, block access to `/go/compare/.*` prior to GoCD Server via a reverse proxy, web application firewall or equivalent, which would prevent use of the pipeline comparison function.

    Published: 20 May 2022
    4.3
    Medium

    CVE-2022-29182

    Last Modified: 23 Apr 2025

    GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Object Model (DOM)-based cross-site scripting attack via a pipeline run's Stage Details > Graphs tab. It is possible for a malicious script on a attacker-hosted site to execute script that will run within the user's browser context and GoCD session via abuse of a messaging channel used for communication between with the parent page and the stage details graph's iframe. This could allow an attacker to steal a GoCD user's session cookies and/or execute malicious code in the user's context. This issue is fixed in GoCD 22.1.0. There are currently no known workarounds.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-28995

    Last Modified: 21 Nov 2024

    Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.

    Published: 20 May 2022
    7.5
    High

    CVE-2022-29179

    Last Modified: 23 Apr 2025

    Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where Cilium is installed, the attacker can escalate privileges to cluster admin by using Cilium's Kubernetes service account. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. There are no known workarounds available.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-28531

    Last Modified: 21 Nov 2024

    Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.

    Published: 20 May 2022
    8.8
    High

    CVE-2022-29178

    Last Modified: 23 Apr 2025

    Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versions 1.9.16, 1.10.11, and 1.11.15 contains an incorrect default permissions vulnerability. Operating Systems with users belonging to the group ID 1000 can access the API of Cilium via Unix domain socket available on the host where Cilium is running. This could allow malicious users to compromise integrity as well as system availability on that host. The problem has been fixed and the patch is available in versions 1.9.16, 1.10.11, and 1.11.5. A potential workaround is to modify Cilium's DaemonSet to run with a certain command, which can be found in the GitHub Security Advisory for this vulnerability.

    Published: 20 May 2022
    7.8
    High

    CVE-2022-28990

    Last Modified: 21 Nov 2024

    WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.wasm.

    Published: 20 May 2022
    8.8
    High

    CVE-2022-1770

    Last Modified: 21 Nov 2024

    Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

    Published: 20 May 2022
    5.9
    Medium

    CVE-2022-22365

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904.

    Published: 20 May 2022
    5.4
    Medium

    CVE-2021-39043

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214032.

    Published: 20 May 2022
    5.9
    Medium

    CVE-2022-29177

    Last Modified: 23 Apr 2025

    Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if configured to use high verbosity logging, can be made to crash when handling specially crafted p2p messages sent from an attacker node. Version 1.10.17 contains a patch that addresses the problem. As a workaround, setting loglevel to default level (`INFO`) makes the node not vulnerable to this attack.

    Published: 20 May 2022
    6.6
    Medium

    CVE-2022-29170

    Last Modified: 23 Apr 2025

    Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a possibility to add a custom datasource to Grafana which returns HTTP redirects. In this scenario, Grafana would blindly follow the redirects and potentially give secure information to the clients. Grafana Cloud is not impacted by this vulnerability. Versions 7.5.16 and 8.5.3 contain a patch for this issue. There are currently no known workarounds.

    Published: 20 May 2022
    3.5
    Low

    CVE-2022-29163

    Last Modified: 23 Apr 2025

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.6 and 23.0.3, a user can create a link that is not password protected even if the administrator requires links to be password protected. Versions 22.2.6 and 23.0.3 contain a patch for this issue. There are currently no known workarounds.

    Published: 20 May 2022
    2.8
    Low

    CVE-2022-29160

    Last Modified: 22 Apr 2025

    Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.

    Published: 20 May 2022
    3.5
    Low

    CVE-2022-24906

    Last Modified: 22 Apr 2025

    Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.

    Published: 20 May 2022
    5
    Medium

    CVE-2022-29159

    Last Modified: 22 Apr 2025

    Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this issue in versions 1.4.8, 1.5.6, and 1.6.1. There are no known currently-known workarounds available.

    Published: 20 May 2022
    7.2
    High

    CVE-2021-30028

    Last Modified: 21 Nov 2024

    SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.

    Published: 20 May 2022
    5.4
    Medium

    CVE-2021-43728

    Last Modified: 21 Nov 2024

    Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized SSID parameter.

    Published: 20 May 2022
    5.4
    Medium

    CVE-2021-43729

    Last Modified: 21 Nov 2024

    Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized Security Key parameter.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-28660

    Last Modified: 21 Nov 2024

    The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

    Published: 20 May 2022
    8.8
    High

    CVE-2022-31245

    Last Modified: 21 Nov 2024

    mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-30886

    Last Modified: 21 Nov 2024

    School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-30887

    Last Modified: 21 Nov 2024

    Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-30518

    Last Modified: 21 Nov 2024

    ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.

    Published: 20 May 2022
    7.8
    High

    CVE-2022-29320

    Last Modified: 21 Nov 2024

    MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

    Published: 20 May 2022
    9.8
    Critical

    CVE-2022-28993

    Last Modified: 21 Nov 2024

    Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.

    Published: 20 May 2022
    8.8
    High

    CVE-2022-28992

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

    Published: 20 May 2022
    7.5
    High

    CVE-2022-28991

    Last Modified: 21 Nov 2024

    Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

    Published: 20 May 2022