CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-22427

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.

    Published: 28 Apr 2022
    5.4
    Medium

    CVE-2022-22322

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218370.

    Published: 28 Apr 2022
    5.4
    Medium

    CVE-2021-38952

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211408.

    Published: 28 Apr 2022
    5.4
    Medium

    CVE-2022-1514

    Last Modified: 21 Nov 2024

    Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

    Published: 28 Apr 2022
    6.1
    Medium

    CVE-2022-29415

    Last Modified: 20 Feb 2025

    Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 at WordPress.

    Published: 28 Apr 2022
    6.1
    Medium

    CVE-2022-27860

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.

    Published: 28 Apr 2022
    7.5
    High

    CVE-2022-29585

    Last Modified: 21 Nov 2024

    In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).

    Published: 28 Apr 2022
    5.4
    Medium

    CVE-2022-29584

    Last Modified: 21 Nov 2024

    Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.

    Published: 28 Apr 2022
    6.5
    Medium

    CVE-2022-22783

    Last Modified: 21 Nov 2024

    A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.

    Published: 28 Apr 2022
    7.9
    High

    CVE-2022-22782

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the user’s host machine.

    Published: 28 Apr 2022
    7.5
    High

    CVE-2022-22781

    Last Modified: 21 Nov 2024

    The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

    Published: 28 Apr 2022
    8.8
    High

    CVE-2021-43939

    Last Modified: 16 Apr 2025

    Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints.

    Published: 28 Apr 2022
    9
    Critical

    CVE-2021-43932

    Last Modified: 16 Apr 2025

    Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.

    Published: 28 Apr 2022
    9.8
    Critical

    CVE-2021-43934

    Last Modified: 16 Apr 2025

    Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.

    Published: 28 Apr 2022
    4.9
    Medium

    CVE-2021-43930

    Last Modified: 16 Apr 2025

    Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.

    Published: 28 Apr 2022
    6.4
    Medium

    CVE-2022-24892

    Last Modified: 23 Apr 2025

    Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's account if they somehow gain access to the victims email account and find an unused password reset token in the emails. This issue is fixed in version 5.7.9.

    Published: 28 Apr 2022
    7.5
    High

    CVE-2022-24879

    Last Modified: 23 Apr 2025

    Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.

    Published: 28 Apr 2022
    4.9
    Medium

    CVE-2022-28117

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

    Published: 28 Apr 2022
    9.1
    Critical

    CVE-2022-28114

    Last Modified: 21 Nov 2024

    DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.

    Published: 28 Apr 2022
    5.4
    Medium

    CVE-2022-28102

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.

    Published: 28 Apr 2022
    9
    Critical

    CVE-2022-28101

    Last Modified: 21 Nov 2024

    Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection.

    Published: 28 Apr 2022
    5.4
    Medium

    CVE-2022-24873

    Last Modified: 23 Apr 2025

    Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.

    Published: 28 Apr 2022
    9.1
    Critical

    CVE-2021-41945

    Last Modified: 21 Nov 2024

    Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.

    Published: 28 Apr 2022
    7.5
    High

    CVE-2022-24935

    Last Modified: 21 Nov 2024

    Lexmark products through 2022-02-10 have Incorrect Access Control.

    Published: 28 Apr 2022
    6.1
    Medium

    CVE-2022-29152

    Last Modified: 21 Nov 2024

    The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.

    Published: 28 Apr 2022
    9.8
    Critical

    CVE-2021-41921

    Last Modified: 21 Nov 2024

    novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.

    Published: 28 Apr 2022
    7.3
    High

    CVE-2021-33436

    Last Modified: 21 Nov 2024

    NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM.

    Published: 28 Apr 2022
    9.9
    Critical

    CVE-2022-1509

    Last Modified: 21 Nov 2024

    Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.

    Published: 28 Apr 2022
    6.9
    Medium

    CVE-2022-29821

    Last Modified: 21 Nov 2024

    In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

    Published: 28 Apr 2022
    3
    Low

    CVE-2022-29820

    Last Modified: 21 Nov 2024

    In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

    Published: 28 Apr 2022
    6.9
    Medium

    CVE-2022-29819

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

    Published: 28 Apr 2022
    3.9
    Low

    CVE-2022-29818

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed

    Published: 28 Apr 2022
    3.9
    Low

    CVE-2022-29817

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible

    Published: 28 Apr 2022
    2.8
    Low

    CVE-2022-29816

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible

    Published: 28 Apr 2022
    6.9
    Medium

    CVE-2022-29815

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

    Published: 28 Apr 2022
    6.9
    Medium

    CVE-2022-29814

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible

    Published: 28 Apr 2022
    6.9
    Medium

    CVE-2022-29813

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

    Published: 28 Apr 2022
    2.3
    Low

    CVE-2022-29812

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient

    Published: 28 Apr 2022
    6.1
    Medium

    CVE-2022-29811

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.

    Published: 28 Apr 2022
    9.8
    Critical

    CVE-2022-28719

    Last Modified: 21 Nov 2024

    Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.

    Published: 28 Apr 2022
    5.5
    Medium

    CVE-2023-23004

    Last Modified: 19 Mar 2025

    In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

    Published: 28 Apr 2022
    6.5
    Medium

    CVE-2022-1511

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.

    Published: 28 Apr 2022
    0
    Low

    CVE-2022-1836

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-33981. Reason: This candidate is a reservation duplicate of CVE-2022-33981. Notes: All CVE users should reference CVE-2022-33981 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Apr 2022
    8.8
    High

    CVE-2022-28892

    Last Modified: 21 Nov 2024

    Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.

    Published: 28 Apr 2022
    5.3
    Medium

    CVE-2022-29869

    Last Modified: 21 Nov 2024

    cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.

    Published: 28 Apr 2022
    —
    Unknown

    CVE-2022-29899

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 28 Apr 2022
    9.8
    Critical

    CVE-2022-29859

    Last Modified: 21 Nov 2024

    component/common/network/dhcp/dhcps.c in ambiot amb1_sdk (aka SDK for Ameba1) before 2022-03-11 mishandles data structures for DHCP packet data.

    Published: 27 Apr 2022
    5
    Medium

    CVE-2022-28197

    Last Modified: 21 Nov 2024

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted data may allow a highly privileged local attacker to cause an integer overflow. This difficult-to-exploit vulnerability may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

    Published: 27 Apr 2022
    4.6
    Medium

    CVE-2022-28196

    Last Modified: 21 Nov 2024

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.

    Published: 27 Apr 2022
    5.7
    Medium

    CVE-2022-28195

    Last Modified: 21 Nov 2024

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

    Published: 27 Apr 2022