CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2021-33124

    Last Modified: 5 May 2025

    Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2021-0189

    Last Modified: 5 May 2025

    Use of out-of-range pointer offset in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2021-33122

    Last Modified: 5 May 2025

    Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2021-0190

    Last Modified: 5 May 2025

    Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2021-33123

    Last Modified: 5 May 2025

    Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2021-0154

    Last Modified: 5 May 2025

    Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2021-0153

    Last Modified: 5 May 2025

    Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

    Published: 12 May 2022
    5.5
    Medium

    CVE-2021-33149

    Last Modified: 5 May 2025

    Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

    Published: 12 May 2022
    6.8
    Medium

    CVE-2022-0004

    Last Modified: 5 May 2025

    Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 12 May 2022
    4.6
    Medium

    CVE-2021-33082

    Last Modified: 5 May 2025

    Sensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 12 May 2022
    4.4
    Medium

    CVE-2021-33083

    Last Modified: 21 Nov 2024

    Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow an privileged user to potentially enable information disclosure via local access.

    Published: 12 May 2022
    5.5
    Medium

    CVE-2021-33069

    Last Modified: 24 Feb 2026

    Improper resource shutdown or release in firmware for some Intel(R) SSD, Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC may allow a privileged user to potentially enable denial of service via local access.

    Published: 12 May 2022
    4.7
    Medium

    CVE-2021-33075

    Last Modified: 5 May 2025

    Race condition in firmware for some Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow a privileged user to potentially enable denial of service via local access.

    Published: 12 May 2022
    4.6
    Medium

    CVE-2021-33074

    Last Modified: 5 May 2025

    Protection mechanism failure in firmware for some Intel(R) SSD, Intel(R) SSD DC and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 12 May 2022
    6.8
    Medium

    CVE-2021-33080

    Last Modified: 5 May 2025

    Exposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products may allow an unauthenticated user to potentially enable information disclosure or escalation of privilege via physical access.

    Published: 12 May 2022
    6.8
    Medium

    CVE-2021-33077

    Last Modified: 5 May 2025

    Insufficient control flow management in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD and Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 12 May 2022
    4.7
    Medium

    CVE-2021-33078

    Last Modified: 5 May 2025

    Race condition within a thread in firmware for some Intel(R) Optane(TM) SSD and Intel(R) SSD DC Products may allow a privileged user to potentially enable denial of service via local access.

    Published: 12 May 2022
    8
    High

    CVE-2021-0126

    Last Modified: 5 May 2025

    Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 12 May 2022
    6.7
    Medium

    CVE-2022-21237

    Last Modified: 5 May 2025

    Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 May 2022
    6.7
    Medium

    CVE-2022-24297

    Last Modified: 5 May 2025

    Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2021-26258

    Last Modified: 5 May 2025

    Improper access control for the Intel(R) Killer(TM) Control Center software before version 2.4.3337.0 may allow an authorized user to potentially enable escalation of privilege via local access.

    Published: 12 May 2022
    6.7
    Medium

    CVE-2022-24382

    Last Modified: 5 May 2025

    Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 May 2022
    7.3
    High

    CVE-2022-22139

    Last Modified: 5 May 2025

    Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 May 2022
    7.8
    High

    CVE-2022-21128

    Last Modified: 5 May 2025

    Insufficient control flow management in the Intel(R) Advisor software before version 7.6.0.37 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 May 2022
    7.2
    High

    CVE-2021-0194

    Last Modified: 5 May 2025

    Improper access control in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

    Published: 12 May 2022
    6.7
    Medium

    CVE-2021-33108

    Last Modified: 5 May 2025

    Improper input validation in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 May 2022
    7.2
    High

    CVE-2021-0193

    Last Modified: 5 May 2025

    Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

    Published: 12 May 2022
    4.6
    Medium

    CVE-2021-33130

    Last Modified: 5 May 2025

    Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 12 May 2022
    4.8
    Medium

    CVE-2022-28920

    Last Modified: 21 Nov 2024

    Tieba-Cloud-Sign v4.9 was discovered to contain a cross-site scripting (XSS) vulnerability via the function strip_tags.

    Published: 12 May 2022
    6.1
    Medium

    CVE-2022-28919

    Last Modified: 21 Nov 2024

    HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29738

    Last Modified: 21 Nov 2024

    Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=transaction/send&id=, id.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29739

    Last Modified: 21 Nov 2024

    Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=user/manage_user&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29307

    Last Modified: 21 Nov 2024

    IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29306

    Last Modified: 21 Nov 2024

    IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29741

    Last Modified: 21 Nov 2024

    Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_fee.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-22413

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29745

    Last Modified: 21 Nov 2024

    Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29746

    Last Modified: 21 Nov 2024

    Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.

    Published: 12 May 2022
    7.5
    High

    CVE-2022-1698

    Last Modified: 21 Nov 2024

    Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

    Published: 12 May 2022
    7.5
    High

    CVE-2022-1699

    Last Modified: 21 Nov 2024

    Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29998

    Last Modified: 22 Apr 2025

    Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/clientStatus.php?client_id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29999

    Last Modified: 22 Apr 2025

    Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29303

    Last Modified: 3 Nov 2025

    SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

    Published: 12 May 2022
    5.5
    Medium

    CVE-2022-29302

    Last Modified: 21 Nov 2024

    SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.

    Published: 12 May 2022
    7.5
    High

    CVE-2022-29298

    Last Modified: 21 Nov 2024

    SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-30000

    Last Modified: 22 Apr 2025

    Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-30001

    Last Modified: 22 Apr 2025

    Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.

    Published: 12 May 2022
    7.2
    High

    CVE-2022-30002

    Last Modified: 22 Apr 2025

    Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editNominee.php?nominee_id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29985

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29986

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.

    Published: 12 May 2022