CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-28821

    Last Modified: 23 Apr 2025

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30387

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order.

    Published: 13 May 2022
    5.3
    Medium

    CVE-2022-27247

    Last Modified: 21 Nov 2024

    onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail information, and phone number) via GastKont Insecure Direct Object Reference.

    Published: 13 May 2022
    8.6
    High

    CVE-2021-22275

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30391

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30392

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30393

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30395

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30396

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30398

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30399

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30400

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30401

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30402

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30403

    Last Modified: 21 Nov 2024

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=products&c=.

    Published: 13 May 2022
    6.5
    Medium

    CVE-2022-30375

    Last Modified: 21 Nov 2024

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30376

    Last Modified: 21 Nov 2024

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30378

    Last Modified: 21 Nov 2024

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30379

    Last Modified: 21 Nov 2024

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.

    Published: 13 May 2022
    6.5
    Medium

    CVE-2022-30367

    Last Modified: 21 Nov 2024

    Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.

    Published: 13 May 2022
    6.8
    Medium

    CVE-2022-29854

    Last Modified: 21 Nov 2024

    A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

    Published: 13 May 2022
    6.1
    Medium

    CVE-2022-30489

    Last Modified: 21 Nov 2024

    WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-29383

    Last Modified: 21 Nov 2024

    NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2022-30370

    Last Modified: 21 Nov 2024

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30371

    Last Modified: 21 Nov 2024

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30372

    Last Modified: 21 Nov 2024

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30373

    Last Modified: 21 Nov 2024

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.

    Published: 13 May 2022
    7.2
    High

    CVE-2022-30374

    Last Modified: 21 Nov 2024

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.

    Published: 13 May 2022
    8.1
    High

    CVE-2020-22983

    Last Modified: 4 Jul 2026

    A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

    Published: 13 May 2022
    8.8
    High

    CVE-2021-42969

    Last Modified: 21 Nov 2024

    Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.

    Published: 13 May 2022
    9.8
    Critical

    CVE-2021-42967

    Last Modified: 21 Nov 2024

    Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.

    Published: 13 May 2022
    7.8
    High

    CVE-2022-1720

    Last Modified: 21 Nov 2024

    Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

    Published: 13 May 2022
    7.5
    High

    CVE-2022-21190

    Last Modified: 21 Nov 2024

    This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-JS-CONVICT-2340604). The [fix](https://github.com/mozilla/node-convict/commit/3b86be087d8f14681a9c889d45da7fe3ad9cd880) introduced, relies on the startsWith method and does not prevent the vulnerability: before splitting the path, it checks if it starts with __proto__ or this.constructor.prototype. To bypass this check it's possible to prepend the dangerous paths with any string value followed by a dot, like for example foo.__proto__ or foo.this.constructor.prototype.

    Published: 13 May 2022
    5.9
    Medium

    CVE-2022-29162

    Last Modified: 23 Apr 2025

    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

    Published: 13 May 2022
    6.3
    Medium

    CVE-2022-1677

    Last Modified: 21 Nov 2024

    In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.

    Published: 13 May 2022
    7.1
    High

    CVE-2022-1714

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

    Published: 13 May 2022
    7.7
    High

    CVE-2022-29218

    Last Modified: 22 Apr 2025

    RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a malicious package. The bug has been patched, and is believed to have never been exploited, based on an extensive review of logs and existing gems by rubygems. The easiest way to ensure that an application has not been exploited by this vulnerability is to verify all downloaded .gems checksums match the checksum recorded in the RubyGems.org database. RubyGems.org has been patched and is no longer vulnerable to this issue.

    Published: 12 May 2022
    7.5
    High

    CVE-2022-27134

    Last Modified: 21 Nov 2024

    EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.

    Published: 12 May 2022
    7.5
    High

    CVE-2021-27777

    Last Modified: 21 Nov 2024

    XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

    Published: 12 May 2022
    4.2
    Medium

    CVE-2021-27773

    Last Modified: 21 Nov 2024

    This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

    Published: 12 May 2022
    7.1
    High

    CVE-2021-27772

    Last Modified: 21 Nov 2024

    Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it. This could lead to information leakage where confidential information discussed in private groups is read by other users without the users knowledge.

    Published: 12 May 2022
    8.2
    High

    CVE-2021-27771

    Last Modified: 21 Nov 2024

    User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

    Published: 12 May 2022
    6.8
    Medium

    CVE-2021-27770

    Last Modified: 21 Nov 2024

    The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will take place.

    Published: 12 May 2022
    5.3
    Medium

    CVE-2021-27769

    Last Modified: 21 Nov 2024

    Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an attack should be limited whenever possible.

    Published: 12 May 2022
    6.3
    Medium

    CVE-2021-27768

    Last Modified: 21 Nov 2024

    Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in 'transparent' mode while a certificate with an invalid hostname was active. The Android application was found to have hostname verification issues during the server setup and login flows; however, the application did not process requests post-login.

    Published: 12 May 2022
    6.1
    Medium

    CVE-2020-22985

    Last Modified: 4 Jul 2026

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

    Published: 12 May 2022
    6.1
    Medium

    CVE-2020-22986

    Last Modified: 4 Jul 2026

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.

    Published: 12 May 2022
    6.1
    Medium

    CVE-2020-22987

    Last Modified: 5 Jul 2026

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

    Published: 12 May 2022
    6.1
    Medium

    CVE-2020-22984

    Last Modified: 4 Jul 2026

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

    Published: 12 May 2022
    6.1
    Medium

    CVE-2022-23166

    Last Modified: 21 Nov 2024

    Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Solution: Update to 22.2.20 cloud version, or to 22.1.64 on premise version.

    Published: 12 May 2022