CVE Feed

    Dashboard / CVE

    5.6
    Medium

    CVE-2021-32010

    Last Modified: 21 Nov 2024

    Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7.

    Published: 4 May 2022
    —
    Unknown

    CVE-2022-28066

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26280. Reason: This candidate is a duplicate of CVE-2022-26280. Notes: All CVE users should reference CVE-2022-26280 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 May 2022
    8.6
    High

    CVE-2022-28067

    Last Modified: 21 Nov 2024

    An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in the Sandbox via a crafted executable.

    Published: 4 May 2022
    8.8
    High

    CVE-2022-28099

    Last Modified: 21 Nov 2024

    Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.

    Published: 4 May 2022
    7.2
    High

    CVE-2022-28076

    Last Modified: 21 Nov 2024

    Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

    Published: 4 May 2022
    8.8
    High

    CVE-2022-27903

    Last Modified: 21 Nov 2024

    An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.

    Published: 4 May 2022
    6.1
    Medium

    CVE-2022-28081

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to execute arbitrary web scripts.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2022-28082

    Last Modified: 21 Nov 2024

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.

    Published: 4 May 2022
    6.5
    Medium

    CVE-2022-28090

    Last Modified: 21 Nov 2024

    Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.

    Published: 4 May 2022
    7.2
    High

    CVE-2022-28096

    Last Modified: 21 Nov 2024

    Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2021-42185

    Last Modified: 21 Nov 2024

    wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.

    Published: 4 May 2022
    6.1
    Medium

    CVE-2022-1571

    Last Modified: 21 Nov 2024

    Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...

    Published: 4 May 2022
    6.1
    Medium

    CVE-2022-1555

    Last Modified: 21 Nov 2024

    DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, deface website, steal cookie...

    Published: 4 May 2022
    4.3
    Medium

    CVE-2022-1502

    Last Modified: 21 Nov 2024

    Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2022-28055

    Last Modified: 21 Nov 2024

    Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.

    Published: 4 May 2022
    7.8
    High

    CVE-2022-27470

    Last Modified: 21 Nov 2024

    SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2022-27431

    Last Modified: 5 May 2025

    Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2022-27420

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

    Published: 4 May 2022
    7.5
    High

    CVE-2022-24901

    Last Modified: 23 Apr 2025

    Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.

    Published: 4 May 2022
    8.8
    High

    CVE-2021-43159

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..

    Published: 4 May 2022
    8.8
    High

    CVE-2021-43162

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.

    Published: 4 May 2022
    8.8
    High

    CVE-2021-43160

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.

    Published: 4 May 2022
    8.8
    High

    CVE-2021-43161

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2021-43163

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.

    Published: 4 May 2022
    8.8
    High

    CVE-2021-43164

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

    Published: 4 May 2022
    8.8
    High

    CVE-2021-42192

    Last Modified: 21 Nov 2024

    Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

    Published: 4 May 2022
    —
    Unknown

    CVE-2021-46793

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 May 2022
    —
    Unknown

    CVE-2021-46796

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 May 2022
    —
    Unknown

    CVE-2021-46799

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 May 2022
    6.5
    Medium

    CVE-2022-1706

    Last Modified: 21 Nov 2024

    A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2022-29155

    Last Modified: 21 Nov 2024

    In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.

    Published: 4 May 2022
    5.5
    Medium

    CVE-2022-1975

    Last Modified: 21 Nov 2024

    There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a nfc device from user-space.

    Published: 4 May 2022
    9.8
    Critical

    CVE-2022-28111

    Last Modified: 21 Nov 2024

    MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.

    Published: 4 May 2022
    7.5
    High

    CVE-2022-28487

    Last Modified: 21 Nov 2024

    Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

    Published: 4 May 2022
    7.3
    High

    CVE-2021-27433

    Last Modified: 16 Apr 2025

    ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-27439

    Last Modified: 16 Apr 2025

    TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-22680

    Last Modified: 16 Apr 2025

    NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-27421

    Last Modified: 16 Apr 2025

    NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.

    Published: 3 May 2022
    9.8
    Critical

    CVE-2022-27413

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-27431

    Last Modified: 16 Apr 2025

    ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-27435

    Last Modified: 16 Apr 2025

    ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-27425

    Last Modified: 16 Apr 2025

    Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-27419

    Last Modified: 16 Apr 2025

    uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

    Published: 3 May 2022
    6.5
    Medium

    CVE-2021-27411

    Last Modified: 16 Apr 2025

    Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small blocks of memory being allocated instead of very large ones.

    Published: 3 May 2022
    4.6
    Medium

    CVE-2021-27417

    Last Modified: 16 Apr 2025

    eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unverified memory assignment can lead to arbitrary memory allocation, resulting in a heap-based buffer overflow.

    Published: 3 May 2022
    7.3
    High

    CVE-2021-27427

    Last Modified: 16 Apr 2025

    RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

    Published: 3 May 2022
    3.7
    Low

    CVE-2022-1548

    Last Modified: 6 Dec 2024

    Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.

    Published: 3 May 2022
    7.8
    High

    CVE-2022-21743

    Last Modified: 21 Nov 2024

    In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: ALPS06371108.

    Published: 3 May 2022
    8.4
    High

    CVE-2022-20111

    Last Modified: 21 Nov 2024

    In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366069; Issue ID: ALPS06366069.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20108

    Last Modified: 21 Nov 2024

    In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330702; Issue ID: DTV03330702.

    Published: 3 May 2022