CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-26378

    Last Modified: 21 Nov 2024

    Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

    Published: 11 May 2022
    4.7
    Medium

    CVE-2021-26347

    Last Modified: 21 Nov 2024

    Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

    Published: 11 May 2022
    3.3
    Low

    CVE-2021-26342

    Last Modified: 21 Nov 2024

    In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.

    Published: 11 May 2022
    5.5
    Medium

    CVE-2021-26375

    Last Modified: 21 Nov 2024

    Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.

    Published: 11 May 2022
    5.5
    Medium

    CVE-2021-26372

    Last Modified: 21 Nov 2024

    Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

    Published: 11 May 2022
    5.5
    Medium

    CVE-2021-26339

    Last Modified: 21 Nov 2024

    A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated by compilers.

    Published: 11 May 2022
    4.7
    Medium

    CVE-2021-26350

    Last Modified: 21 Nov 2024

    A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.

    Published: 11 May 2022
    4.8
    Medium

    CVE-2022-22320

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218367.

    Published: 11 May 2022
    5.4
    Medium

    CVE-2021-39059

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214619.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2021-38969

    Last Modified: 21 Nov 2024

    IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.

    Published: 11 May 2022
    8.4
    High

    CVE-2021-43066

    Last Modified: 21 Nov 2024

    A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.

    Published: 11 May 2022
    6.6
    Medium

    CVE-2022-22975

    Last Modified: 21 Nov 2024

    An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user entry on the LDAP or AD server to include special characters, which could be used to perform LDAP query injection on the Supervisor's LDAP query which determines their Kubernetes group membership.

    Published: 11 May 2022
    6.1
    Medium

    CVE-2022-23137

    Last Modified: 21 Nov 2024

    ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.

    Published: 11 May 2022
    7.5
    High

    CVE-2022-29616

    Last Modified: 21 Nov 2024

    SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption.

    Published: 11 May 2022
    4.3
    Medium

    CVE-2022-29613

    Last Modified: 21 Nov 2024

    Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application.

    Published: 11 May 2022
    8.8
    High

    CVE-2022-29611

    Last Modified: 21 Nov 2024

    SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 11 May 2022
    5.4
    Medium

    CVE-2022-29610

    Last Modified: 21 Nov 2024

    SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.

    Published: 11 May 2022
    5.5
    Medium

    CVE-2022-28774

    Last Modified: 21 Nov 2024

    Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.

    Published: 11 May 2022
    7.8
    High

    CVE-2022-28214

    Last Modified: 21 Nov 2024

    During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and Availability.

    Published: 11 May 2022
    6.1
    Medium

    CVE-2022-27656

    Last Modified: 21 Nov 2024

    The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 11 May 2022
    4.3
    Medium

    CVE-2022-1124

    Last Modified: 21 Nov 2024

    An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

    Published: 11 May 2022
    6.5
    Medium

    CVE-2022-1510

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline details page allowing the attacker to cause uncontrolled resource consumption.

    Published: 11 May 2022
    6.1
    Medium

    CVE-2022-1460

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations on scheduled pipelines allowing a malicious user to run a pipeline in the context of another user.

    Published: 11 May 2022
    6.5
    Medium

    CVE-2022-1406

    Last Modified: 21 Nov 2024

    Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0 allows a Developer to read protected Group or Project CI/CD variables by importing a malicious project

    Published: 11 May 2022
    4.3
    Medium

    CVE-2022-1428

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was incorrectly verifying throttling limits for authenticated package requests which resulted in limits not being enforced.

    Published: 11 May 2022
    2
    Low

    CVE-2022-1426

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.

    Published: 11 May 2022
    6.1
    Medium

    CVE-2021-43081

    Last Modified: 21 Nov 2024

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.

    Published: 11 May 2022
    5.3
    Medium

    CVE-2022-1352

    Last Modified: 21 Nov 2024

    Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an endpoint may reveal the issue title to a user who crafted an API call with the ID of the issue from a public project that restricts access to issue only to project members.

    Published: 11 May 2022
    2.6
    Low

    CVE-2022-1433

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.

    Published: 11 May 2022
    9.1
    Critical

    CVE-2022-29898

    Last Modified: 21 Nov 2024

    On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.

    Published: 11 May 2022
    9.1
    Critical

    CVE-2022-29897

    Last Modified: 21 Nov 2024

    On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.

    Published: 11 May 2022
    7.3
    High

    CVE-2021-34606

    Last Modified: 21 Nov 2024

    A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnerability. This means the potential attacker must have access to the system and sufficient file-write privileges. If exploited, the attacker could place a malicious DLL file on the system, that when running XINJE XD/E Series PLC Program Tool will allow the attacker to execute arbitrary code with the privileges of another user's account.

    Published: 11 May 2022
    7.3
    High

    CVE-2021-34605

    Last Modified: 21 Nov 2024

    A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.

    Published: 11 May 2022
    4.3
    Medium

    CVE-2022-1545

    Last Modified: 21 Nov 2024

    It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged in the note.

    Published: 11 May 2022
    6.8
    Medium

    CVE-2021-44167

    Last Modified: 21 Nov 2024

    An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6.4.7 and below, 7.0.2 and below may allow an unauthenticated attacker to access sensitive information in log files and directories via symbolic links.

    Published: 11 May 2022
    8.8
    High

    CVE-2021-42651

    Last Modified: 21 Nov 2024

    A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.

    Published: 11 May 2022
    7.3
    High

    CVE-2021-37851

    Last Modified: 21 Nov 2024

    Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet Security 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Smart Security Premium 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Endpoint Antivirus 6.0 versions prior to 9.0.2046.0; 6.0 versions prior to 8.1.2050.0; 6.0 versions prior to 8.0.2053.0. ESET, spol. s r.o. ESET Endpoint Security 6.0 versions prior to 9.0.2046.0; 6.0 versions prior to 8.1.2050.0; 6.0 versions prior to 8.0.2053.0. ESET, spol. s r.o. ESET Server Security for Microsoft Windows Server 8.0 versions prior to 9.0.12012.0. ESET, spol. s r.o. ESET File Security for Microsoft Windows Server 8.0.12013.0. ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server 6.0 versions prior to 8.0.10020.0. ESET, spol. s r.o. ESET Mail Security for IBM Domino 6.0 versions prior to 8.0.14011.0. ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server 6.0 versions prior to 8.0.15009.0.

    Published: 11 May 2022
    6.1
    Medium

    CVE-2022-28078

    Last Modified: 21 Nov 2024

    Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

    Published: 11 May 2022
    6.1
    Medium

    CVE-2022-28077

    Last Modified: 21 Nov 2024

    Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

    Published: 11 May 2022
    7.5
    High

    CVE-2022-29932

    Last Modified: 21 Nov 2024

    The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.

    Published: 11 May 2022
    6.5
    Medium

    CVE-2022-29978

    Last Modified: 24 Apr 2026

    There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.

    Published: 11 May 2022
    6.5
    Medium

    CVE-2022-29977

    Last Modified: 24 Apr 2026

    There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-29009

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

    Published: 11 May 2022
    6.5
    Medium

    CVE-2022-29008

    Last Modified: 21 Nov 2024

    An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-29007

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-29006

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

    Published: 11 May 2022
    6.1
    Medium

    CVE-2022-29728

    Last Modified: 21 Nov 2024

    Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.

    Published: 11 May 2022
    9.8
    Critical

    CVE-2022-29656

    Last Modified: 21 Nov 2024

    Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.

    Published: 11 May 2022
    7.2
    High

    CVE-2022-29655

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 11 May 2022
    7.2
    High

    CVE-2022-29318

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 11 May 2022