CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2022-28194

    Last Modified: 21 Nov 2024

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.

    Published: 27 Apr 2022
    5.6
    Medium

    CVE-2022-28193

    Last Modified: 21 Nov 2024

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of integrity, limited denial of service, and some impact to confidentiality.

    Published: 27 Apr 2022
    8.8
    High

    CVE-2022-22315

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.

    Published: 27 Apr 2022
    4.6
    Medium

    CVE-2022-24372

    Last Modified: 21 Nov 2024

    Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.

    Published: 27 Apr 2022
    5.5
    Medium

    CVE-2022-1507

    Last Modified: 21 Nov 2024

    chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.

    Published: 27 Apr 2022
    3.9
    Low

    CVE-2021-25266

    Last Modified: 21 Nov 2024

    An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2022-22278

    Last Modified: 21 Nov 2024

    A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

    Published: 27 Apr 2022
    5.3
    Medium

    CVE-2022-22277

    Last Modified: 21 Nov 2024

    A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.

    Published: 27 Apr 2022
    5.3
    Medium

    CVE-2022-22276

    Last Modified: 21 Nov 2024

    A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2022-22275

    Last Modified: 21 Nov 2024

    Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.

    Published: 27 Apr 2022
    6.8
    Medium

    CVE-2022-23822

    Last Modified: 21 Nov 2024

    In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as using the device as a decryption oracle. An anticipated mitigation via a 2022.1 patch will resolve the issue.

    Published: 27 Apr 2022
    4.8
    Medium

    CVE-2022-22345

    Last Modified: 21 Nov 2024

    IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041.

    Published: 27 Apr 2022
    6.5
    Medium

    CVE-2022-22323

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 218379.

    Published: 27 Apr 2022
    6.5
    Medium

    CVE-2022-22312

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 217369.

    Published: 27 Apr 2022
    5.3
    Medium

    CVE-2021-38939

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2021-38919

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021

    Published: 27 Apr 2022
    7.5
    High

    CVE-2021-38878

    Last Modified: 21 Nov 2024

    IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.

    Published: 27 Apr 2022
    4.3
    Medium

    CVE-2021-38874

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397.

    Published: 27 Apr 2022
    9.8
    Critical

    CVE-2021-38869

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.

    Published: 27 Apr 2022
    4.3
    Medium

    CVE-2021-29776

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030.

    Published: 27 Apr 2022
    9.8
    Critical

    CVE-2022-27336

    Last Modified: 21 Nov 2024

    Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.

    Published: 27 Apr 2022
    7.3
    High

    CVE-2022-22521

    Last Modified: 21 Nov 2024

    In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

    Published: 27 Apr 2022
    8.8
    High

    CVE-2021-34602

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.

    Published: 27 Apr 2022
    9.8
    Critical

    CVE-2021-34601

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.

    Published: 27 Apr 2022
    8.8
    High

    CVE-2021-34592

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.

    Published: 27 Apr 2022
    7.8
    High

    CVE-2021-34591

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.

    Published: 27 Apr 2022
    5.4
    Medium

    CVE-2021-34590

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker could write HTML Code into configuration values. These values are not properly escaped when displayed.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2021-34589

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.

    Published: 27 Apr 2022
    8.6
    High

    CVE-2021-34588

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .

    Published: 27 Apr 2022
    5.3
    Medium

    CVE-2021-34587

    Last Modified: 21 Nov 2024

    In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.

    Published: 27 Apr 2022
    2.4
    Low

    CVE-2022-24889

    Last Modified: 22 Apr 2025

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they do not need, thus expanding their attack surface unnecessarily. This issue is fixed in versions 21.0.8 , 22.2.4, and 23.0.1.

    Published: 27 Apr 2022
    7.8
    High

    CVE-2022-29505

    Last Modified: 21 Nov 2024

    Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.

    Published: 27 Apr 2022
    4.3
    Medium

    CVE-2022-24888

    Last Modified: 23 Apr 2025

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1, it is possible to create files and folders that have leading and trailing \n, \r, \t, and \v characters. The server rejects files and folders that have these characters in the middle of their names, so this might be an opportunity for injection. This issue is fixed in versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1. There are currently no known workarounds.

    Published: 27 Apr 2022
    7.2
    High

    CVE-2022-27905

    Last Modified: 21 Nov 2024

    In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.

    Published: 27 Apr 2022
    4.3
    Medium

    CVE-2022-24887

    Last Modified: 22 Apr 2025

    Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs. This issue is fixed in versions 11.3.4, 12.2.2, and 13.0.0. There are currently no known workarounds.

    Published: 27 Apr 2022
    2.2
    Low

    CVE-2022-24886

    Last Modified: 23 Apr 2025

    Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Contacts permission itself. Version 3.19.0 contains a fix for this issue. There are currently no known workarounds.

    Published: 27 Apr 2022
    2
    Low

    CVE-2022-24885

    Last Modified: 22 Apr 2025

    Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1, users can bypass a lock on the Nextcloud app on an Android device by repeatedly reopening the app. Version 3.19.1 contains a fix for the problem. There are currently no known workarounds.

    Published: 27 Apr 2022
    9
    Critical

    CVE-2022-28464

    Last Modified: 21 Nov 2024

    Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.

    Published: 27 Apr 2022
    9.1
    Critical

    CVE-2021-46424

    Last Modified: 21 Nov 2024

    Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

    Published: 27 Apr 2022
    5.3
    Medium

    CVE-2021-46423

    Last Modified: 21 Nov 2024

    Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker to download a full configuration file.

    Published: 27 Apr 2022
    9.8
    Critical

    CVE-2021-46422

    Last Modified: 21 Nov 2024

    Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2021-46421

    Last Modified: 21 Nov 2024

    Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2021-46420

    Last Modified: 21 Nov 2024

    Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.

    Published: 27 Apr 2022
    6.1
    Medium

    CVE-2022-1504

    Last Modified: 21 Nov 2024

    XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.

    Published: 27 Apr 2022
    8.8
    High

    CVE-2021-46441

    Last Modified: 21 Nov 2024

    In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.

    Published: 27 Apr 2022
    9.8
    Critical

    CVE-2021-46442

    Last Modified: 21 Nov 2024

    In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.

    Published: 27 Apr 2022
    3.5
    Low

    CVE-2022-1503

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> leads to cross site scripting. The attack may be launched remotely but requires authentication. Expoit details have been disclosed within the advisory.

    Published: 27 Apr 2022
    8.1
    High

    CVE-2022-22576

    Last Modified: 16 Apr 2026

    An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

    Published: 27 Apr 2022
    5.7
    Medium

    CVE-2022-27774

    Last Modified: 16 Apr 2026

    An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2022-29700

    Last Modified: 21 Nov 2024

    A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.

    Published: 27 Apr 2022