CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-27634

    Last Modified: 21 Nov 2024

    On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authenticated attacker with high privileges to manipulate the APM policy leading to privilege escalation/remote code execution. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    6.5
    Medium

    CVE-2022-27495

    Last Modified: 21 Nov 2024

    On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    7.5
    High

    CVE-2022-27230

    Last Modified: 21 Nov 2024

    On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of F5 BIG-IP Guided Configuration that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    7.5
    High

    CVE-2022-27189

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configured on a virtual server, undisclosed traffic can cause an increase in Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    5.3
    Medium

    CVE-2022-27182

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters are enabled and a virtual server is configured with the type set to Reject, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    5.3
    Medium

    CVE-2022-27181

    Last Modified: 21 Nov 2024

    On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when APM is configured on a virtual server and the associated access profile is configured with APM AAA NTLM Auth, undisclosed requests can cause an increase in internal resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    8.8
    High

    CVE-2022-28080

    Last Modified: 21 Nov 2024

    Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.

    Published: 5 May 2022
    7.5
    High

    CVE-2022-26890

    Last Modified: 21 Nov 2024

    On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when ASM or Advanced WAF, as well as APM, are configured on a virtual server, the ASM policy is configured with Session Awareness, and the "Use APM Username and Session ID" option is enabled, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    4.9
    Medium

    CVE-2022-26835

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, directory traversal vulnerabilities exist in undisclosed iControl REST endpoints and TMOS Shell (tmsh) commands in F5 BIG-IP Guided Configuration, which may allow an authenticated attacker with at least resource administrator role privileges to read arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 5 May 2022
    9.8
    Critical

    CVE-2022-28120

    Last Modified: 21 Nov 2024

    Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.

    Published: 5 May 2022
    4.6
    Medium

    CVE-2022-22434

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API request modified to create additional objects. IBM X-Force ID: 224159.

    Published: 5 May 2022
    7.5
    High

    CVE-2022-22433

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 224156.

    Published: 5 May 2022
    9.8
    Critical

    CVE-2022-28606

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.

    Published: 5 May 2022
    6.5
    Medium

    CVE-2022-22415

    Last Modified: 21 Nov 2024

    A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029.

    Published: 5 May 2022
    5.3
    Medium

    CVE-2021-39020

    Last Modified: 21 Nov 2024

    IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 213855.

    Published: 5 May 2022
    9.8
    Critical

    CVE-2022-29592

    Last Modified: 21 Nov 2024

    Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

    Published: 5 May 2022
    8.8
    High

    CVE-2022-28079

    Last Modified: 21 Nov 2024

    College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.

    Published: 5 May 2022
    6.6
    Medium

    CVE-2021-38435

    Last Modified: 16 Apr 2025

    RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocating the buffer, which may result in a buffer overflow.

    Published: 5 May 2022
    6.6
    Medium

    CVE-2021-38433

    Last Modified: 16 Apr 2025

    RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.

    Published: 5 May 2022
    6.6
    Medium

    CVE-2021-38429

    Last Modified: 16 Apr 2025

    OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-of-service condition and information exposure.

    Published: 5 May 2022
    6.6
    Medium

    CVE-2021-38427

    Last Modified: 16 Apr 2025

    RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.

    Published: 5 May 2022
    7.5
    High

    CVE-2021-38425

    Last Modified: 16 Apr 2025

    eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, which may result in a denial-of-service condition and information exposure.

    Published: 5 May 2022
    6.6
    Medium

    CVE-2021-38423

    Last Modified: 16 Apr 2025

    All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buffer overflow.

    Published: 5 May 2022
    7.5
    High

    CVE-2021-43547

    Last Modified: 16 Apr 2025

    TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.

    Published: 5 May 2022
    8.8
    High

    CVE-2021-38487

    Last Modified: 23 Jun 2025

    RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.

    Published: 5 May 2022
    8.6
    High

    CVE-2021-38447

    Last Modified: 16 Apr 2025

    OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-of-service condition.

    Published: 5 May 2022
    7
    High

    CVE-2021-38445

    Last Modified: 16 Apr 2025

    OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbitrary code.

    Published: 5 May 2022
    6.6
    Medium

    CVE-2021-38443

    Last Modified: 16 Apr 2025

    Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

    Published: 5 May 2022
    6.6
    Medium

    CVE-2021-38441

    Last Modified: 16 Apr 2025

    Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.

    Published: 5 May 2022
    8.6
    High

    CVE-2021-38439

    Last Modified: 16 Apr 2025

    All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or remotely execute arbitrary code.

    Published: 5 May 2022
    5.4
    Medium

    CVE-2022-1464

    Last Modified: 21 Nov 2024

    Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .

    Published: 5 May 2022
    7.5
    High

    CVE-2021-42183

    Last Modified: 21 Nov 2024

    MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.

    Published: 5 May 2022
    7.5
    High

    CVE-2022-29340

    Last Modified: 21 Nov 2024

    GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.

    Published: 5 May 2022
    7.5
    High

    CVE-2022-29339

    Last Modified: 21 Nov 2024

    In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.

    Published: 5 May 2022
    6.5
    Medium

    CVE-2022-28471

    Last Modified: 21 Nov 2024

    In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38

    Published: 5 May 2022
    7.5
    High

    CVE-2022-28462

    Last Modified: 21 Nov 2024

    novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.

    Published: 5 May 2022
    9.8
    Critical

    CVE-2022-28461

    Last Modified: 21 Nov 2024

    mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.

    Published: 5 May 2022
    9.8
    Critical

    CVE-2021-42242

    Last Modified: 21 Nov 2024

    A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

    Published: 5 May 2022
    9.6
    Critical

    CVE-2022-1575

    Last Modified: 21 Nov 2024

    Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.

    Published: 5 May 2022
    8.8
    High

    CVE-2022-29938

    Last Modified: 21 Nov 2024

    In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.

    Published: 5 May 2022
    5.4
    Medium

    CVE-2022-29939

    Last Modified: 21 Nov 2024

    In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.

    Published: 5 May 2022
    5.4
    Medium

    CVE-2022-29940

    Last Modified: 21 Nov 2024

    In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.

    Published: 5 May 2022
    9.8
    Critical

    CVE-2021-41739

    Last Modified: 22 Jan 2026

    A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.

    Published: 5 May 2022
    6.1
    Medium

    CVE-2022-1411

    Last Modified: 21 Nov 2024

    Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

    Published: 5 May 2022
    4.6
    Medium

    CVE-2021-45783

    Last Modified: 21 Nov 2024

    Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.

    Published: 5 May 2022
    8.2
    High

    CVE-2022-1592

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...

    Published: 5 May 2022
    3.5
    Low

    CVE-2022-1590

    Last Modified: 15 Apr 2025

    A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires an authentication. The exploit has been disclosed to the public and may be used.

    Published: 5 May 2022
    9.8
    Critical

    CVE-2022-28890

    Last Modified: 21 Nov 2024

    A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

    Published: 5 May 2022
    —
    Unknown

    CVE-2022-1588

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 May 2022
    3.3
    Low

    CVE-2022-32296

    Last Modified: 21 Nov 2024

    The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

    Published: 5 May 2022