CVE Feed

    Dashboard / CVE

    4.1
    Medium

    CVE-2022-29449

    Last Modified: 20 Feb 2025

    Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booking plugin <= 1.2.7 at WordPress.

    Published: 19 May 2022
    6.8
    Medium

    CVE-2022-29446

    Last Modified: 20 Feb 2025

    Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.

    Published: 19 May 2022
    9.8
    Critical

    CVE-2021-37413

    Last Modified: 21 Nov 2024

    GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

    Published: 19 May 2022
    8
    High

    CVE-2021-26631

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the total order amount into a negative number and then pay for the order.

    Published: 19 May 2022
    7.8
    High

    CVE-2021-26630

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.

    Published: 19 May 2022
    6
    Medium

    CVE-2021-45730

    Last Modified: 21 Nov 2024

    JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.

    Published: 19 May 2022
    7.2
    High

    CVE-2021-41938

    Last Modified: 21 Nov 2024

    An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.

    Published: 19 May 2022
    4.6
    Medium

    CVE-2022-1730

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.

    Published: 19 May 2022
    8.8
    High

    CVE-2022-30018

    Last Modified: 21 Nov 2024

    Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file. The credential storage method in this software enables an attacker/user of the machine to gain admin access to the software and gain access to recordings/recording locations.

    Published: 19 May 2022
    7.5
    High

    CVE-2022-1670

    Last Modified: 21 Nov 2024

    When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

    Published: 19 May 2022
    9.8
    Critical

    CVE-2022-28349

    Last Modified: 21 Nov 2024

    Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.

    Published: 19 May 2022
    9.8
    Critical

    CVE-2022-28350

    Last Modified: 21 Nov 2024

    Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.

    Published: 19 May 2022
    9.8
    Critical

    CVE-2022-28348

    Last Modified: 21 Nov 2024

    Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.

    Published: 19 May 2022
    7.8
    High

    CVE-2022-1785

    Last Modified: 3 Nov 2025

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

    Published: 19 May 2022
    7.8
    High

    CVE-2022-1796

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 8.2.4979.

    Published: 19 May 2022
    7.5
    High

    CVE-2022-28948

    Last Modified: 21 Nov 2024

    An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

    Published: 19 May 2022
    8.2
    High

    CVE-2022-29181

    Last Modified: 27 May 2025

    Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.

    Published: 19 May 2022
    —
    Unknown

    CVE-2022-31227

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 19 May 2022
    —
    Unknown

    CVE-2022-31242

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 19 May 2022
    9.8
    Critical

    CVE-2022-1736

    Last Modified: 26 Aug 2025

    Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

    Published: 19 May 2022
    7.8
    High

    CVE-2022-30138

    Last Modified: 2 Jan 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 18 May 2022
    6.3
    Medium

    CVE-2022-29229

    Last Modified: 23 Apr 2025

    CaSS is a Competency and Skills System. CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cryptographic keys that can allow a server administrator access to an account’s cryptographic keys. This affects CaSS servers using standalone username/password authentication, which uses a method that expects e2e cryptographic security of authorization credentials. The issue has been patched in 1.5.8, however, the vulnerable accounts are only resecured when the user next logs in using standalone authentication, as the data required to resecure the account is not available to the server. The issue may be mitigated by using SSO or client side certificates to log in. Please note that SSO and client side certificate authentication does not have this expectation of no-knowledge credential access, and cryptographic keys are available to the server administrator.

    Published: 18 May 2022
    6.1
    Medium

    CVE-2022-1774

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.

    Published: 18 May 2022
    6.3
    Medium

    CVE-2022-29230

    Last Modified: 23 Apr 2025

    Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of Hydrogen starting from version 0.10.0 to 0.18.0. This vulnerability is exploitable in applications whose hydrating data is user controlled. All Hydrogen users should upgrade their project to version 0.19.0. There is no current workaround, and users should update as soon as possible. Additionally, the Content Security Policy is not an effective mitigation for this vulnerability.

    Published: 18 May 2022
    6.1
    Medium

    CVE-2022-30991

    Last Modified: 21 Nov 2024

    HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

    Published: 18 May 2022
    6.1
    Medium

    CVE-2022-30992

    Last Modified: 21 Nov 2024

    Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

    Published: 18 May 2022
    7.5
    High

    CVE-2022-30993

    Last Modified: 21 Nov 2024

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

    Published: 18 May 2022
    7.5
    High

    CVE-2022-30994

    Last Modified: 21 Nov 2024

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240

    Published: 18 May 2022
    7.5
    High

    CVE-2022-30990

    Last Modified: 21 Nov 2024

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037

    Published: 18 May 2022
    6.1
    Medium

    CVE-2021-38944

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 211236.

    Published: 18 May 2022
    7.5
    High

    CVE-2022-30033

    Last Modified: 21 Nov 2024

    Tenda TX9 Pro V22.03.02.10 is vulnerable to Buffer Overflow via the functtion setIPv6Status() in httpd module.

    Published: 18 May 2022
    4.7
    Medium

    CVE-2022-25617

    Last Modified: 20 Feb 2025

    Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.

    Published: 18 May 2022
    9.8
    Critical

    CVE-2022-30600

    Last Modified: 21 Nov 2024

    A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

    Published: 18 May 2022
    6.8
    Medium

    CVE-2022-30111

    Last Modified: 21 Nov 2024

    Due to the use of an insecure algorithm for rolling codes in MCK Smartlock 1.0, allows attackers to unlock the mechanism via replay attacks.

    Published: 18 May 2022
    6.5
    Medium

    CVE-2022-28921

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.

    Published: 18 May 2022
    9.8
    Critical

    CVE-2022-30599

    Last Modified: 21 Nov 2024

    A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

    Published: 18 May 2022
    4.3
    Medium

    CVE-2022-30598

    Last Modified: 21 Nov 2024

    A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

    Published: 18 May 2022
    5.3
    Medium

    CVE-2022-30597

    Last Modified: 21 Nov 2024

    A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

    Published: 18 May 2022
    8.8
    High

    CVE-2022-22778

    Last Modified: 21 Nov 2024

    The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

    Published: 18 May 2022
    6.1
    Medium

    CVE-2022-22777

    Last Modified: 21 Nov 2024

    The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow an unauthenticated attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

    Published: 18 May 2022
    8
    High

    CVE-2022-22776

    Last Modified: 21 Nov 2024

    The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

    Published: 18 May 2022
    5.4
    Medium

    CVE-2022-30596

    Last Modified: 21 Nov 2024

    A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

    Published: 18 May 2022
    6.8
    Medium

    CVE-2022-29445

    Last Modified: 20 Feb 2025

    Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.

    Published: 18 May 2022
    7.3
    High

    CVE-2022-0883

    Last Modified: 21 Nov 2024

    SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.

    Published: 18 May 2022
    5.3
    Medium

    CVE-2022-25162

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior and versions prior to 1.073, MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 179**** and prior and versions prior to 1.073, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DSS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MR/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/z(x=24,40,60, y=T,R, z=ES,ESS) versions prior to 1.030, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/ES-A(x=24,40,60, y=T,R) versions prior to 1.031 and Mitsubishi Electric MELSEC iQ-F series FX5S-xMy/z(x=30,40,60,80, y=T,R, z=ES,ESS) version 1.000 allows a remote unauthenticated attacker to cause a temporary DoS condition for the product's communication by sending specially crafted packets.

    Published: 18 May 2022
    6.5
    Medium

    CVE-2022-28924

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/.

    Published: 18 May 2022
    8.6
    High

    CVE-2022-25161

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior and versions prior to 1.073, MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 179**** and prior and versions prior to 1.073, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DSS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MR/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/z(x=24,40,60, y=T,R, z=ES,ESS) versions prior to 1.030, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/ES-A(x=24,40,60, y=T,R) versions prior to 1.031 and Mitsubishi Electric MELSEC iQ-F series FX5S-xMy/z(x=30,40,60,80, y=T,R, z=ES,ESS) version 1.000 allows a remote unauthenticated attacker to cause a DoS condition for the product's program execution or communication by sending specially crafted packets. System reset of the product is required for recovery.

    Published: 18 May 2022
    5.5
    Medium

    CVE-2022-1110

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.

    Published: 18 May 2022
    8
    High

    CVE-2021-42852

    Last Modified: 21 Nov 2024

    A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.

    Published: 18 May 2022
    6.3
    Medium

    CVE-2021-42851

    Last Modified: 21 Nov 2024

    A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.

    Published: 18 May 2022