CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2021-42643

    Last Modified: 21 Nov 2024

    cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.

    Published: 17 May 2022
    5.4
    Medium

    CVE-2021-42943

    Last Modified: 21 Nov 2024

    Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrary web script or HTML via the userid parameter.

    Published: 17 May 2022
    7.5
    High

    CVE-2022-1723

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.

    Published: 17 May 2022
    7.5
    High

    CVE-2022-26650

    Last Modified: 21 Nov 2024

    In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.

    Published: 17 May 2022
    4.8
    Medium

    CVE-2013-10001

    Last Modified: 15 Apr 2025

    A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail client. An exploit has been disclosed to the public and may be used.

    Published: 17 May 2022
    5.4
    Medium

    CVE-2022-1753

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.

    Published: 17 May 2022
    7.8
    High

    CVE-2022-1921

    Last Modified: 17 Mar 2026

    Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.

    Published: 17 May 2022
    7.8
    High

    CVE-2022-1733

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.

    Published: 17 May 2022
    7.8
    High

    CVE-2022-1769

    Last Modified: 21 Nov 2024

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-26700

    Last Modified: 22 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to code execution.

    Published: 17 May 2022
    7.7
    High

    CVE-2022-28183

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause an out-of-bounds read, which may lead to denial of service and information disclosure.

    Published: 17 May 2022
    7.1
    High

    CVE-2022-28184

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.

    Published: 17 May 2022
    6.8
    Medium

    CVE-2022-28185

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.

    Published: 17 May 2022
    7.2
    High

    CVE-2022-30007

    Last Modified: 21 Nov 2024

    GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server.

    Published: 17 May 2022
    9.8
    Critical

    CVE-2022-30595

    Last Modified: 21 Nov 2024

    libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.

    Published: 17 May 2022
    5.3
    Medium

    CVE-2022-30689

    Last Modified: 21 Nov 2024

    HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.

    Published: 17 May 2022
    7.5
    High

    CVE-2022-30948

    Last Modified: 21 Nov 2024

    Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

    Published: 17 May 2022
    6.5
    Medium

    CVE-2022-30953

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server.

    Published: 17 May 2022
    7.8
    High

    CVE-2022-1735

    Last Modified: 21 Nov 2024

    Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-26719

    Last Modified: 6 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 17 May 2022
    5.3
    Medium

    CVE-2022-22976

    Last Modified: 21 Nov 2024

    Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-26709

    Last Modified: 6 May 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-26716

    Last Modified: 6 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 17 May 2022
    8.8
    High

    CVE-2022-26717

    Last Modified: 6 May 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 17 May 2022
    8.5
    High

    CVE-2022-28181

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

    Published: 17 May 2022
    5.5
    Medium

    CVE-2022-30067

    Last Modified: 21 Nov 2024

    GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

    Published: 17 May 2022
    4.3
    Medium

    CVE-2022-30946

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.

    Published: 17 May 2022
    6.5
    Medium

    CVE-2022-30952

    Last Modified: 21 Nov 2024

    Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.

    Published: 17 May 2022
    8.5
    High

    CVE-2022-30945

    Last Modified: 21 Nov 2024

    Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.

    Published: 17 May 2022
    6.5
    Medium

    CVE-2022-30954

    Last Modified: 21 Nov 2024

    Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

    Published: 17 May 2022
    6.5
    Medium

    CVE-2022-23670

    Last Modified: 21 Nov 2024

    A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    7.2
    High

    CVE-2022-23667

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    4.9
    Medium

    CVE-2022-23668

    Last Modified: 21 Nov 2024

    A remote authenticated server-side request forgery (ssrf) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manage that address this security vulnerability.

    Published: 16 May 2022
    9.1
    Critical

    CVE-2022-23666

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    9.1
    Critical

    CVE-2022-23665

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    9.1
    Critical

    CVE-2022-23664

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    9.1
    Critical

    CVE-2022-23661

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    9.1
    Critical

    CVE-2022-23662

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    9.1
    Critical

    CVE-2022-23663

    Last Modified: 21 Nov 2024

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    10
    Critical

    CVE-2022-23660

    Last Modified: 21 Nov 2024

    A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    6.1
    Medium

    CVE-2022-23659

    Last Modified: 21 Nov 2024

    A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    10
    Critical

    CVE-2022-23658

    Last Modified: 21 Nov 2024

    A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    10
    Critical

    CVE-2022-23657

    Last Modified: 21 Nov 2024

    A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

    Published: 16 May 2022
    9.8
    Critical

    CVE-2022-1731

    Last Modified: 21 Nov 2024

    Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.

    Published: 16 May 2022
    5.6
    Medium

    CVE-2021-33025

    Last Modified: 16 Apr 2025

    xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

    Published: 16 May 2022
    6.1
    Medium

    CVE-2021-33021

    Last Modified: 16 Apr 2025

    xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.

    Published: 16 May 2022
    6.1
    Medium

    CVE-2021-33001

    Last Modified: 16 Apr 2025

    xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.

    Published: 16 May 2022
    7.8
    High

    CVE-2022-30697

    Last Modified: 21 Nov 2024

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

    Published: 16 May 2022
    7.8
    High

    CVE-2022-30696

    Last Modified: 21 Nov 2024

    Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

    Published: 16 May 2022
    7.8
    High

    CVE-2022-30695

    Last Modified: 21 Nov 2024

    Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

    Published: 16 May 2022