CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-29701

    Last Modified: 21 Nov 2024

    A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 27 Apr 2022
    9.1
    Critical

    CVE-2022-27332

    Last Modified: 21 Nov 2024

    An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

    Published: 27 Apr 2022
    4.3
    Medium

    CVE-2022-27331

    Last Modified: 21 Nov 2024

    An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only be visible to authenticated users.

    Published: 27 Apr 2022
    7.8
    High

    CVE-2022-28085

    Last Modified: 5 Feb 2025

    A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).

    Published: 27 Apr 2022
    6.1
    Medium

    CVE-2022-22577

    Last Modified: 21 Nov 2024

    An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.

    Published: 27 Apr 2022
    5.5
    Medium

    CVE-2022-29799

    Last Modified: 27 May 2025

    A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.

    Published: 27 Apr 2022
    3.9
    Low

    CVE-2022-24735

    Last Modified: 22 Apr 2025

    Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution environment in Redis provides some measures that prevent a script from creating side effects that persist and can affect the execution of the same, or different script, at a later time. Several weaknesses of these measures have been publicly known for a long time, but they had no security impact as the Redis security model did not endorse the concept of users or privileges. With the introduction of ACLs in Redis 6.0, these weaknesses can be exploited by a less privileged users to inject Lua code that will execute at a later time, when a privileged user executes a Lua script. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

    Published: 27 Apr 2022
    3.3
    Low

    CVE-2022-24736

    Last Modified: 22 Apr 2025

    Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

    Published: 27 Apr 2022
    4.7
    Medium

    CVE-2022-29800

    Last Modified: 28 May 2025

    A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

    Published: 27 Apr 2022
    5.5
    Medium

    CVE-2022-29810

    Last Modified: 21 Nov 2024

    The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.

    Published: 27 Apr 2022
    5.3
    Medium

    CVE-2021-41041

    Last Modified: 21 Nov 2024

    In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.

    Published: 27 Apr 2022
    7.8
    High

    CVE-2022-1419

    Last Modified: 21 Nov 2024

    The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created in *vgem_gem_dumb_create*) concurrently, and *vgem_gem_dumb_create *will access the freed drm_vgem_gem_object.

    Published: 27 Apr 2022
    7.8
    High

    CVE-2022-27239

    Last Modified: 21 Nov 2024

    In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

    Published: 27 Apr 2022
    6.5
    Medium

    CVE-2022-27776

    Last Modified: 21 Nov 2024

    A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

    Published: 27 Apr 2022
    6.1
    Medium

    CVE-2022-27777

    Last Modified: 21 Nov 2024

    A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.

    Published: 27 Apr 2022
    7.5
    High

    CVE-2022-27775

    Last Modified: 27 May 2026

    An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.

    Published: 27 Apr 2022
    5.4
    Medium

    CVE-2022-24891

    Last Modified: 3 Nov 2025

    ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause "javascript:" URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround, manually edit the **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression. More information about remediation of the vulnerability, including the workaround, is available in the maintainers' release notes and security bulletin.

    Published: 27 Apr 2022
    5.5
    Medium

    CVE-2022-27888

    Last Modified: 21 Nov 2024

    Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This issue was fixed in 2.249.1.

    Published: 26 Apr 2022
    6.1
    Medium

    CVE-2022-26564

    Last Modified: 21 Nov 2024

    HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.

    Published: 26 Apr 2022
    8.1
    High

    CVE-2022-28918

    Last Modified: 21 Nov 2024

    GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=.

    Published: 26 Apr 2022
    8.1
    High

    CVE-2022-28527

    Last Modified: 21 Nov 2024

    dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.

    Published: 26 Apr 2022
    8.8
    High

    CVE-2022-28528

    Last Modified: 21 Nov 2024

    bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-28524

    Last Modified: 21 Nov 2024

    ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.

    Published: 26 Apr 2022
    8.8
    High

    CVE-2022-28525

    Last Modified: 21 Nov 2024

    ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.

    Published: 26 Apr 2022
    8.1
    High

    CVE-2022-28523

    Last Modified: 21 Nov 2024

    HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

    Published: 26 Apr 2022
    5.4
    Medium

    CVE-2022-28522

    Last Modified: 21 Nov 2024

    ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-28521

    Last Modified: 21 Nov 2024

    ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.

    Published: 26 Apr 2022
    8.1
    High

    CVE-2022-28058

    Last Modified: 21 Nov 2024

    Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.

    Published: 26 Apr 2022
    8.1
    High

    CVE-2022-28059

    Last Modified: 21 Nov 2024

    Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.

    Published: 26 Apr 2022
    5.4
    Medium

    CVE-2022-28450

    Last Modified: 21 Nov 2024

    nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.

    Published: 26 Apr 2022
    6.1
    Medium

    CVE-2022-28449

    Last Modified: 21 Nov 2024

    nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.

    Published: 26 Apr 2022
    5.4
    Medium

    CVE-2022-28448

    Last Modified: 21 Nov 2024

    nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.

    Published: 26 Apr 2022
    4.3
    Medium

    CVE-2022-24866

    Last Modified: 23 Apr 2025

    Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to version 1.0.1, the UserBookmarkSerializer serialized the whole User / Group object, which leaked some private information. The data was only being serialized to people who could view assignment info, which is limited to staff by default. For the vast majority of sites, this data was only leaked to trusted staff member, but for sites with assign features enabled publicly, the data was accessible to more people than just staff. Version 1.0.1 contains a patch. There are currently no known workarounds.

    Published: 26 Apr 2022
    5.4
    Medium

    CVE-2022-27854

    Last Modified: 20 Feb 2025

    Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_caption parameter.

    Published: 26 Apr 2022
    8.1
    High

    CVE-2021-26628

    Last Modified: 21 Nov 2024

    Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as image files.

    Published: 26 Apr 2022
    8.8
    High

    CVE-2021-26629

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.

    Published: 26 Apr 2022
    4.7
    Medium

    CVE-2021-36895

    Last Modified: 20 Feb 2025

    Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG image upload.

    Published: 26 Apr 2022
    5.4
    Medium

    CVE-2021-36867

    Last Modified: 20 Feb 2025

    Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher user rights.

    Published: 26 Apr 2022
    5.5
    Medium

    CVE-2022-28218

    Last Modified: 21 Nov 2024

    An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configuration file) that are used to protect Webmail user passwords and two-factor authentication (2FA).

    Published: 26 Apr 2022
    5.5
    Medium

    CVE-2022-0851

    Last Modified: 21 Nov 2024

    There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the activation key via the process command line via e.g. htop or ps. The specific impact varies upon the subscription, but generally this would allow an attacker to register systems purchased by the victim until discovered; a form of fraud. This could occur regardless of how the activation key is supplied to convert2rhel because it involves how convert2rhel provides it to subscription-manager.

    Published: 26 Apr 2022
    5.4
    Medium

    CVE-2022-1173

    Last Modified: 21 Nov 2024

    stored xss in GitHub repository getgrav/grav prior to 1.7.33.

    Published: 26 Apr 2022
    8.8
    High

    CVE-2022-24881

    Last Modified: 22 Apr 2025

    Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.

    Published: 26 Apr 2022
    7.5
    High

    CVE-2022-23942

    Last Modified: 21 Nov 2024

    Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

    Published: 26 Apr 2022
    5.5
    Medium

    CVE-2022-0852

    Last Modified: 21 Nov 2024

    There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact varies upon the privileges of the Red Hat account in question, but it could affect the integrity, availability, and/or data confidentiality of other systems that are administered by that account. This occurs regardless of how the password is supplied to convert2rhel.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-27985

    Last Modified: 21 Nov 2024

    CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-27984

    Last Modified: 21 Nov 2024

    CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-27469

    Last Modified: 21 Nov 2024

    Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-27468

    Last Modified: 21 Nov 2024

    Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-27299

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.

    Published: 26 Apr 2022
    9.8
    Critical

    CVE-2022-29806

    Last Modified: 21 Nov 2024

    ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.

    Published: 26 Apr 2022