CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2022-26597

    Last Modified: 5 Jul 2026

    Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.

    Published: 25 Apr 2022
    8.8
    High

    CVE-2022-26111

    Last Modified: 21 Nov 2024

    The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server.

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2022-28094

    Last Modified: 21 Nov 2024

    SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-28093

    Last Modified: 21 Nov 2024

    SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-27311

    Last Modified: 21 Nov 2024

    Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.

    Published: 25 Apr 2022
    5.5
    Medium

    CVE-2022-27135

    Last Modified: 21 Nov 2024

    xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.

    Published: 25 Apr 2022
    8.8
    High

    CVE-2022-28053

    Last Modified: 21 Nov 2024

    Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-27429

    Last Modified: 21 Nov 2024

    Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.

    Published: 25 Apr 2022
    5.4
    Medium

    CVE-2022-27428

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the album_name parameter.

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2022-28586

    Last Modified: 21 Nov 2024

    XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payload bypass filter some special chars.

    Published: 25 Apr 2022
    6.1
    Medium

    CVE-2022-27103

    Last Modified: 21 Nov 2024

    element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.

    Published: 25 Apr 2022
    7.8
    High

    CVE-2021-36460

    Last Modified: 21 Nov 2024

    VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.

    Published: 25 Apr 2022
    8.8
    High

    CVE-2021-45836

    Last Modified: 21 Nov 2024

    An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2021-45840

    Last Modified: 21 Nov 2024

    It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.

    Published: 25 Apr 2022
    7.5
    High

    CVE-2021-45842

    Last Modified: 21 Nov 2024

    It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS endpoint.

    Published: 25 Apr 2022
    6.5
    Medium

    CVE-2022-1461

    Last Modified: 21 Nov 2024

    Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

    Published: 25 Apr 2022
    4.3
    Medium

    CVE-2022-28871

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scanning larger packages/fuzzed files consume too much memory eventually can crash the scanning engine. The exploit can be triggered remotely by an attacker.

    Published: 25 Apr 2022
    8.3
    High

    CVE-2022-1459

    Last Modified: 21 Nov 2024

    Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.

    Published: 25 Apr 2022
    5.4
    Medium

    CVE-2022-1458

    Last Modified: 21 Nov 2024

    Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.

    Published: 25 Apr 2022
    5.4
    Medium

    CVE-2022-1457

    Last Modified: 21 Nov 2024

    Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascripts prior to 2022.04. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-29264

    Last Modified: 21 Nov 2024

    An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.

    Published: 25 Apr 2022
    —
    Unknown

    CVE-2021-36628

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-40680. Reason: This candidate is a reservation duplicate of CVE-2021-40680. Notes: All CVE users should reference CVE-2021-40680 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Apr 2022
    8.1
    High

    CVE-2021-40680

    Last Modified: 21 Nov 2024

    There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.

    Published: 25 Apr 2022
    8.1
    High

    CVE-2022-29603

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API endpoints. A remote authenticated attacker could send crafted SQL statements to a vulnerable endpoint (such as /api/students/me/messages/) to, for example, retrieve personal information or change grades.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-29077

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This exposes all digital assets on the XRPL to a security threat.

    Published: 25 Apr 2022
    7.5
    High

    CVE-2022-29546

    Last Modified: 21 Nov 2024

    HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the product.

    Published: 25 Apr 2022
    7.5
    High

    CVE-2022-23457

    Last Modified: 3 Nov 2025

    ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow control-flow bypass checks to be defeated if an attack can specify the entire string representing the 'input' path. This vulnerability is patched in release 2.3.0.0 of ESAPI. As a workaround, it is possible to write one's own implementation of the Validator interface. However, maintainers do not recommend this.

    Published: 25 Apr 2022
    8.1
    High

    CVE-2021-45841

    Last Modified: 21 Nov 2024

    In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker to login as guest.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2021-45837

    Last Modified: 21 Nov 2024

    It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.

    Published: 25 Apr 2022
    6.5
    Medium

    CVE-2021-45839

    Last Modified: 21 Nov 2024

    It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint.

    Published: 25 Apr 2022
    7.8
    High

    CVE-2022-1441

    Last Modified: 21 Nov 2024

    MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content read from `bs` is controllable by user, so is the length, which causes a buffer overflow.

    Published: 25 Apr 2022
    7.5
    High

    CVE-2022-24792

    Last Modified: 23 Apr 2025

    PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerability occurs when reading WAV file data chunks with length greater than 31-bit integers. The vulnerability does not affect 64-bit apps and should not affect apps that only plays trusted WAV files. A patch is available on the `master` branch of the `pjsip/project` GitHub repository. As a workaround, apps can reject a WAV file received from an unknown source or validate the file first.

    Published: 25 Apr 2022
    7.8
    High

    CVE-2019-25059

    Last Modified: 21 Nov 2024

    Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

    Published: 25 Apr 2022
    5.5
    Medium

    CVE-2022-28506

    Last Modified: 21 Nov 2024

    There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.

    Published: 25 Apr 2022
    9.8
    Critical

    CVE-2022-29078

    Last Modified: 21 Nov 2024

    The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

    Published: 25 Apr 2022
    7.1
    High

    CVE-2022-1451

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

    Published: 24 Apr 2022
    7.1
    High

    CVE-2022-1452

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

    Published: 24 Apr 2022
    5.4
    Medium

    CVE-2022-1445

    Last Modified: 21 Nov 2024

    Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

    Published: 24 Apr 2022
    5.5
    Medium

    CVE-2022-1444

    Last Modified: 21 Nov 2024

    heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing denial of service.

    Published: 23 Apr 2022
    —
    Unknown

    CVE-2022-1443

    Last Modified: 19 Aug 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1789. Reason: This candidate is a reservation duplicate of CVE-2024-1789. Notes: All CVE users should reference CVE-2024-1789 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 23 Apr 2022
    7.8
    High

    CVE-2022-1427

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

    Published: 22 Apr 2022
    9.8
    Critical

    CVE-2021-3897

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

    Published: 22 Apr 2022
    9.8
    Critical

    CVE-2021-3849

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

    Published: 22 Apr 2022
    6.7
    Medium

    CVE-2022-1108

    Last Modified: 21 Nov 2024

    A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 22 Apr 2022
    6.7
    Medium

    CVE-2022-1107

    Last Modified: 21 Nov 2024

    During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.

    Published: 22 Apr 2022
    5
    Medium

    CVE-2022-0636

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.

    Published: 22 Apr 2022
    7.3
    High

    CVE-2022-0354

    Last Modified: 2 Jun 2026

    A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command prompt window.

    Published: 22 Apr 2022
    7.3
    High

    CVE-2022-0192

    Last Modified: 21 Nov 2024

    A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.

    Published: 22 Apr 2022
    6.7
    Medium

    CVE-2021-4212

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 22 Apr 2022
    6.7
    Medium

    CVE-2021-4211

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.

    Published: 22 Apr 2022