CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-29987

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29988

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29989

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29990

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/view_category.php?id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29992

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=.

    Published: 12 May 2022
    7.5
    High

    CVE-2022-30279

    Last Modified: 21 Nov 2024

    An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29993

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/bookings/view_booking.php?id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29994

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29995

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=clients/manage_client&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29747

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29748

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29749

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29750

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29751

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29981

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.

    Published: 12 May 2022
    5.3
    Medium

    CVE-2022-29538

    Last Modified: 21 Nov 2024

    RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able to access some critical resources.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29979

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29539

    Last Modified: 21 Nov 2024

    resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\ commands) and inject arbitrary system commands with the privileges of the application user.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29980

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29982

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29983

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-29984

    Last Modified: 21 Nov 2024

    Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-30525

    Last Modified: 27 Oct 2025

    A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2021-42863

    Last Modified: 21 Nov 2024

    A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.

    Published: 12 May 2022
    4.3
    Medium

    CVE-2022-28873

    Last Modified: 21 Nov 2024

    A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.open functionality in SAFE Browser which could lead address bar spoofing attacks.

    Published: 12 May 2022
    4.3
    Medium

    CVE-2022-28872

    Last Modified: 21 Nov 2024

    A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing attack with address bar spoofing as the address bar was not correct if navigation fails in a loop.

    Published: 12 May 2022
    8.7
    High

    CVE-2022-29930

    Last Modified: 21 Nov 2024

    SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

    Published: 12 May 2022
    3.7
    Low

    CVE-2022-29929

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible

    Published: 12 May 2022
    4.4
    Medium

    CVE-2022-29928

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible

    Published: 12 May 2022
    4.6
    Medium

    CVE-2022-29927

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible

    Published: 12 May 2022
    6.1
    Medium

    CVE-2022-1682

    Last Modified: 21 Nov 2024

    Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser

    Published: 12 May 2022
    6.5
    Medium

    CVE-2022-1044

    Last Modified: 21 Nov 2024

    Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.

    Published: 12 May 2022
    7.2
    High

    CVE-2022-1681

    Last Modified: 21 Nov 2024

    Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

    Published: 12 May 2022
    8.6
    High

    CVE-2022-25762

    Last Modified: 25 Aug 2026

    If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

    Published: 12 May 2022
    7.8
    High

    CVE-2022-30594

    Last Modified: 21 Nov 2024

    The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.

    Published: 12 May 2022
    5.5
    Medium

    CVE-2022-1674

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.

    Published: 12 May 2022
    8.8
    High

    CVE-2022-1552

    Last Modified: 21 Nov 2024

    A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.

    Published: 12 May 2022
    7.4
    High

    CVE-2022-29217

    Last Modified: 23 Apr 2025

    PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always be explicit with the algorithms that are accepted and expected when decoding.

    Published: 12 May 2022
    8.1
    High

    CVE-2022-1650

    Last Modified: 24 Feb 2026

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

    Published: 12 May 2022
    9.8
    Critical

    CVE-2022-30592

    Last Modified: 21 Nov 2024

    liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

    Published: 11 May 2022
    7.5
    High

    CVE-2022-30557

    Last Modified: 21 Nov 2024

    Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.

    Published: 11 May 2022
    6.8
    Medium

    CVE-2022-29855

    Last Modified: 21 Nov 2024

    Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-29596

    Last Modified: 21 Nov 2024

    MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-30449

    Last Modified: 21 Nov 2024

    Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-30450

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php

    Published: 11 May 2022
    8.8
    High

    CVE-2022-30451

    Last Modified: 21 Nov 2024

    An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-30448

    Last Modified: 21 Nov 2024

    Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-30063

    Last Modified: 21 Nov 2024

    ftcms <=2.1 was discovered to be vulnerable to code execution attacks .

    Published: 11 May 2022
    6.5
    Medium

    CVE-2022-30062

    Last Modified: 21 Nov 2024

    ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php

    Published: 11 May 2022
    7.8
    High

    CVE-2022-28838

    Last Modified: 27 May 2026

    Acrobat Acrobat Pro DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 May 2022