CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-22281

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.

    Published: 13 May 2022
    6.1
    Medium

    CVE-2022-1702

    Last Modified: 21 Nov 2024

    SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-1701

    Last Modified: 21 Nov 2024

    SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-1715

    Last Modified: 21 Nov 2024

    Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.

    Published: 13 May 2022
    6.5
    Medium

    CVE-2022-22393

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078.

    Published: 13 May 2022
    5.5
    Medium

    CVE-2022-22325

    Last Modified: 21 Nov 2024

    IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a local user from a stack trace. IBM X-Force ID: 218853.

    Published: 13 May 2022
    4.1
    Medium

    CVE-2022-29433

    Last Modified: 20 Feb 2025

    Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.

    Published: 13 May 2022
    8.2
    High

    CVE-2021-33013

    Last Modified: 16 Apr 2025

    mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.

    Published: 13 May 2022
    7.5
    High

    CVE-2021-33009

    Last Modified: 16 Apr 2025

    mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.

    Published: 13 May 2022
    7.5
    High

    CVE-2021-33005

    Last Modified: 16 Apr 2025

    mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.

    Published: 13 May 2022
    7.5
    High

    CVE-2021-27505

    Last Modified: 16 Apr 2025

    mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-22252

    Last Modified: 21 Nov 2024

    The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30411

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-29796

    Last Modified: 21 Nov 2024

    The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-29795

    Last Modified: 21 Nov 2024

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-29794

    Last Modified: 21 Nov 2024

    The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-29793

    Last Modified: 21 Nov 2024

    There is a configuration defect in the activation lock of mobile phones.Successful exploitation of this vulnerability may affect application availability.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-29792

    Last Modified: 21 Nov 2024

    The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30412

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.php?id=.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-29791

    Last Modified: 21 Nov 2024

    The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-29790

    Last Modified: 21 Nov 2024

    The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-29789

    Last Modified: 21 Nov 2024

    The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-22261

    Last Modified: 21 Nov 2024

    The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.

    Published: 13 May 2022
    9.1
    Critical

    CVE-2022-22260

    Last Modified: 21 Nov 2024

    The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.

    Published: 13 May 2022
    7.5
    High

    CVE-2021-46789

    Last Modified: 21 Nov 2024

    Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30413

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application.

    Published: 13 May 2022
    7.5
    High

    CVE-2021-46788

    Last Modified: 21 Nov 2024

    Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.

    Published: 13 May 2022
    7.5
    High

    CVE-2021-46787

    Last Modified: 21 Nov 2024

    The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2021-46786

    Last Modified: 21 Nov 2024

    The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.

    Published: 13 May 2022
    5.3
    Medium

    CVE-2021-46785

    Last Modified: 21 Nov 2024

    The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique device identifier.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30414

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=applications/view_application&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30415

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.php?id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30417

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=.

    Published: 13 May 2022
    6.5
    Medium

    CVE-2022-30408

    Last Modified: 21 Nov 2024

    Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30407

    Last Modified: 21 Nov 2024

    Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30404

    Last Modified: 21 Nov 2024

    College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.

    Published: 13 May 2022
    6.5
    Medium

    CVE-2022-30381

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30384

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30385

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.

    Published: 13 May 2022
    5.5
    Medium

    CVE-2022-28830

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28829

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    9.1
    Critical

    CVE-2022-25591

    Last Modified: 21 Nov 2024

    BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28828

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28827

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28826

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28825

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28824

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30386

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28823

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-28822

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022