CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-0191

    Last Modified: 21 Nov 2024

    The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans

    Published: 2 May 2022
    4.7
    Medium

    CVE-2021-25102

    Last Modified: 21 Nov 2024

    The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk

    Published: 2 May 2022
    6.1
    Medium

    CVE-2021-25086

    Last Modified: 21 Nov 2024

    The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it

    Published: 2 May 2022
    7.5
    High

    CVE-2021-25002

    Last Modified: 21 Nov 2024

    The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL

    Published: 2 May 2022
    —
    Unknown

    CVE-2021-32500

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 May 2022
    9.8
    Critical

    CVE-2022-28056

    Last Modified: 21 Nov 2024

    ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.

    Published: 2 May 2022
    9.8
    Critical

    CVE-2022-28054

    Last Modified: 21 Nov 2024

    Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.

    Published: 2 May 2022
    7.5
    High

    CVE-2022-27983

    Last Modified: 21 Nov 2024

    RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain an arbitrary file read vulnerability via the url parameter in check.php.

    Published: 2 May 2022
    9.8
    Critical

    CVE-2022-27982

    Last Modified: 21 Nov 2024

    RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the fileName parameter at /guest_auth/cfg/upLoadCfg.php.

    Published: 2 May 2022
    9.8
    Critical

    CVE-2022-27466

    Last Modified: 21 Nov 2024

    MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.

    Published: 2 May 2022
    9.8
    Critical

    CVE-2022-28573

    Last Modified: 21 Nov 2024

    D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone parameter.

    Published: 2 May 2022
    8.8
    High

    CVE-2022-28572

    Last Modified: 21 Nov 2024

    Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function

    Published: 2 May 2022
    9.8
    Critical

    CVE-2022-28571

    Last Modified: 21 Nov 2024

    D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.

    Published: 2 May 2022
    5.4
    Medium

    CVE-2022-23065

    Last Modified: 21 Nov 2024

    In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.

    Published: 2 May 2022
    8.8
    High

    CVE-2022-23064

    Last Modified: 21 Nov 2024

    In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.

    Published: 2 May 2022
    8
    High

    CVE-2022-23904

    Last Modified: 21 Nov 2024

    Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.

    Published: 2 May 2022
    9.8
    Critical

    CVE-2022-1300

    Last Modified: 21 Nov 2024

    Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.

    Published: 2 May 2022
    5.4
    Medium

    CVE-2021-4200

    Last Modified: 21 Nov 2024

    A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.

    Published: 2 May 2022
    7.2
    High

    CVE-2021-36784

    Last Modified: 21 Nov 2024

    A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.

    Published: 2 May 2022
    7.3
    High

    CVE-2021-36778

    Last Modified: 21 Nov 2024

    A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

    Published: 2 May 2022
    4.7
    Medium

    CVE-2022-29973

    Last Modified: 21 Nov 2024

    relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in certain situations involving offsets beyond ValidDataLength.

    Published: 2 May 2022
    8.2
    High

    CVE-2022-1012

    Last Modified: 21 Nov 2024

    A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.

    Published: 2 May 2022
    7.8
    High

    CVE-2022-29968

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.

    Published: 2 May 2022
    8.4
    High

    CVE-2022-1117

    Last Modified: 21 Nov 2024

    A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker, a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.

    Published: 2 May 2022
    6.1
    Medium

    CVE-2022-29969

    Last Modified: 21 Nov 2024

    The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist and $wgRSSAllowLinkTag is true).

    Published: 2 May 2022
    7.5
    High

    CVE-2022-29970

    Last Modified: 4 Nov 2025

    Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

    Published: 2 May 2022
    5.5
    Medium

    CVE-2022-1475

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.

    Published: 2 May 2022
    7.8
    High

    CVE-2022-29849

    Last Modified: 21 Nov 2024

    In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escalation. If exploited, a local attacker could elevate their privileges and compromise the affected system.

    Published: 1 May 2022
    7.5
    High

    CVE-2021-40822

    Last Modified: 21 Nov 2024

    GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

    Published: 1 May 2022
    7.5
    High

    CVE-2022-28451

    Last Modified: 21 Nov 2024

    nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.

    Published: 1 May 2022
    6.1
    Medium

    CVE-2021-31673

    Last Modified: 21 Nov 2024

    A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

    Published: 1 May 2022
    6.1
    Medium

    CVE-2021-31674

    Last Modified: 4 Jul 2026

    Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

    Published: 1 May 2022
    7.7
    High

    CVE-2022-25301

    Last Modified: 21 Nov 2024

    All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.

    Published: 1 May 2022
    5.4
    Medium

    CVE-2022-21149

    Last Modified: 21 Nov 2024

    The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.

    Published: 1 May 2022
    9.8
    Critical

    CVE-2022-25767

    Last Modified: 21 Nov 2024

    All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

    Published: 1 May 2022
    5.4
    Medium

    CVE-2022-25349

    Last Modified: 21 Nov 2024

    All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as &lt;not-a-tag /&gt;) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.

    Published: 1 May 2022
    7.5
    High

    CVE-2022-21167

    Last Modified: 21 Nov 2024

    All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.

    Published: 1 May 2022
    6.5
    Medium

    CVE-2022-26068

    Last Modified: 21 Nov 2024

    This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.

    Published: 1 May 2022
    6.9
    Medium

    CVE-2022-25842

    Last Modified: 21 Nov 2024

    All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.

    Published: 1 May 2022
    8.6
    High

    CVE-2022-23923

    Last Modified: 21 Nov 2024

    All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.

    Published: 1 May 2022
    7.3
    High

    CVE-2022-21189

    Last Modified: 21 Nov 2024

    The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the Dexie.setByKeyPath(obj, keyPath, value) function which does not properly check the keys being set (like __proto__ or constructor). This can allow an attacker to add/modify properties of the Object.prototype leading to prototype pollution vulnerability. **Note:** This vulnerability can occur in multiple ways, for example when modifying a collection with untrusted user input.

    Published: 1 May 2022
    7.5
    High

    CVE-2022-21144

    Last Modified: 21 Nov 2024

    This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.

    Published: 1 May 2022
    5.5
    Medium

    CVE-2022-21230

    Last Modified: 21 Nov 2024

    This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP request, the body of the request is written to a RandomAccessFile when the it is larger than 1024 bytes. This file is created with insecure permissions that allow its contents to be viewed by all users on the host machine. **Workaround:** Manually specifying the -Djava.io.tmpdir= argument when launching Java to set the temporary directory to a directory exclusively controlled by the current user can fix this issue.

    Published: 1 May 2022
    9.8
    Critical

    CVE-2022-24437

    Last Modified: 21 Nov 2024

    The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.

    Published: 1 May 2022
    7.5
    High

    CVE-2022-25850

    Last Modified: 21 Nov 2024

    The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.

    Published: 1 May 2022
    9.8
    Critical

    CVE-2022-28481

    Last Modified: 21 Nov 2024

    CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.

    Published: 1 May 2022
    6.5
    Medium

    CVE-2022-23061

    Last Modified: 21 Nov 2024

    In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Reference (IDOR) vulnerability.

    Published: 1 May 2022
    4.8
    Medium

    CVE-2022-23060

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged user (attacker) can inject malicious JavaScript in the filename under the “Manage files” tab

    Published: 1 May 2022
    7.8
    High

    CVE-2022-1544

    Last Modified: 21 Nov 2024

    Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.

    Published: 1 May 2022
    7.7
    High

    CVE-2022-25647

    Last Modified: 22 May 2026

    The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

    Published: 1 May 2022