CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-27530

    Last Modified: 21 Nov 2024

    A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability may be exploited to execute arbitrary code.

    Published: 18 Apr 2022
    7.8
    High

    CVE-2022-27529

    Last Modified: 21 Nov 2024

    A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond the allocated buffer while parsing PICT, BMP, PSD or TIF file. This vulnerability may be exploited to execute arbitrary code.

    Published: 18 Apr 2022
    7.8
    High

    CVE-2022-27526

    Last Modified: 21 Nov 2024

    A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 18 Apr 2022
    7.8
    High

    CVE-2022-27525

    Last Modified: 21 Nov 2024

    A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 18 Apr 2022
    7.8
    High

    CVE-2020-6099

    Last Modified: 15 Apr 2025

    An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop Viewer 2019.2.2328. A specially crafted file can cause a heap buffer overflow resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 18 Apr 2022
    7.2
    High

    CVE-2020-13590

    Last Modified: 15 Apr 2025

    Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities, this can be done either with administrator credentials or through cross-site request forgery.

    Published: 18 Apr 2022
    9.8
    Critical

    CVE-2020-13567

    Last Modified: 15 Apr 2025

    Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 18 Apr 2022
    5.5
    Medium

    CVE-2020-13495

    Last Modified: 15 Apr 2025

    An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the disclosure of sensitive information. This vulnerability could be used to bypass mitigations and aid additional exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided file.

    Published: 18 Apr 2022
    7.2
    High

    CVE-2021-46122

    Last Modified: 21 Nov 2024

    Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.

    Published: 18 Apr 2022
    7.5
    High

    CVE-2022-26665

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.

    Published: 18 Apr 2022
    9.8
    Critical

    CVE-2022-26631

    Last Modified: 21 Nov 2024

    Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.

    Published: 18 Apr 2022
    6.8
    Medium

    CVE-2022-28810

    Last Modified: 31 Oct 2025

    Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

    Published: 18 Apr 2022
    8.8
    High

    CVE-2022-27908

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.

    Published: 18 Apr 2022
    5.5
    Medium

    CVE-2022-1184

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.

    Published: 18 Apr 2022
    9.8
    Critical

    CVE-2022-29464

    Last Modified: 7 Nov 2025

    Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

    Published: 18 Apr 2022
    6.2
    Medium

    CVE-2022-24859

    Last Modified: 22 Apr 2025

    PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In versions prior to 1.27.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if the PyPDF2 if the code attempts to get the content stream. The reason is that the last while-loop in `ContentStream._readInlineImage` only terminates when it finds the `EI` token, but never actually checks if the stream has already ended. This issue has been resolved in version `1.27.5`. Users unable to upgrade should validate and PDFs prior to iterating over their content stream.

    Published: 18 Apr 2022
    7.5
    High

    CVE-2022-24863

    Last Modified: 23 Apr 2025

    http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a denial of service attack consisting of memory exhaustion on the host system. The cause of the memory exhaustion is down to improper handling of http methods. Users are advised to upgrade. Users unable to upgrade may to restrict the path prefix to the "GET" method as a workaround.

    Published: 18 Apr 2022
    7.1
    High

    CVE-2022-29458

    Last Modified: 9 Jun 2025

    ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

    Published: 18 Apr 2022
    6.1
    Medium

    CVE-2022-1383

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

    Published: 17 Apr 2022
    7.8
    High

    CVE-2022-1381

    Last Modified: 21 Nov 2024

    global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

    Published: 17 Apr 2022
    5.5
    Medium

    CVE-2022-29654

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file.

    Published: 17 Apr 2022
    5.5
    Medium

    CVE-2022-1382

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.

    Published: 16 Apr 2022
    5.5
    Medium

    CVE-2022-28966

    Last Modified: 21 Nov 2024

    Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectly from Compile_BranchTable in m3_compile.c).

    Published: 16 Apr 2022
    5.3
    Medium

    CVE-2022-26653

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).

    Published: 16 Apr 2022
    5.3
    Medium

    CVE-2022-26777

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.

    Published: 16 Apr 2022
    5.4
    Medium

    CVE-2022-1380

    Last Modified: 21 Nov 2024

    Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.

    Published: 16 Apr 2022
    4.9
    Medium

    CVE-2022-29287

    Last Modified: 19 Dec 2025

    Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user options of any user, even ones with higher privileges (like Global Administrators) than the current user. The exported XML contains every option of the exported user (even the hashed password).

    Published: 15 Apr 2022
    6.1
    Medium

    CVE-2022-29020

    Last Modified: 21 Nov 2024

    ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar.

    Published: 15 Apr 2022
    6.5
    Medium

    CVE-2022-1365

    Last Modified: 21 Nov 2024

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.

    Published: 15 Apr 2022
    8.8
    High

    CVE-2022-29281

    Last Modified: 21 Nov 2024

    Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

    Published: 15 Apr 2022
    7.5
    High

    CVE-2022-24279

    Last Modified: 21 Nov 2024

    The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676)

    Published: 15 Apr 2022
    7.8
    High

    CVE-2022-29072

    Last Modified: 9 Jun 2025

    7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur

    Published: 15 Apr 2022
    —
    Unknown

    CVE-2022-27427

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-38745. Reason: This candidate is a duplicate of CVE-2021-38745. Notes: All CVE users should reference CVE-2021-38745 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Apr 2022
    8.8
    High

    CVE-2022-27426

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.

    Published: 15 Apr 2022
    6.1
    Medium

    CVE-2022-27425

    Last Modified: 21 Nov 2024

    Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php.

    Published: 15 Apr 2022
    9.8
    Critical

    CVE-2022-27423

    Last Modified: 21 Nov 2024

    Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.

    Published: 15 Apr 2022
    7.2
    High

    CVE-2022-27421

    Last Modified: 21 Nov 2024

    Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.

    Published: 15 Apr 2022
    6.1
    Medium

    CVE-2022-27422

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2022-26924

    Last Modified: 2 Jan 2025

    YARP Denial of Service Vulnerability

    Published: 15 Apr 2022
    7.3
    High

    CVE-2022-26921

    Last Modified: 2 Jan 2025

    Visual Studio Code Elevation of Privilege Vulnerability

    Published: 15 Apr 2022
    5.5
    Medium

    CVE-2022-26920

    Last Modified: 2 Jan 2025

    Windows Graphics Component Information Disclosure Vulnerability

    Published: 15 Apr 2022
    8.1
    High

    CVE-2022-26919

    Last Modified: 2 Jan 2025

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.8
    High

    CVE-2022-26918

    Last Modified: 2 Jan 2025

    Windows Fax Compose Form Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.8
    High

    CVE-2022-26917

    Last Modified: 16 Dec 2025

    Windows Fax Compose Form Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.8
    High

    CVE-2022-26916

    Last Modified: 16 Dec 2025

    Windows Fax Compose Form Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.5
    High

    CVE-2022-26915

    Last Modified: 2 Jan 2025

    Windows Secure Channel Denial of Service Vulnerability

    Published: 15 Apr 2022
    7.8
    High

    CVE-2022-26914

    Last Modified: 2 Jan 2025

    Win32k Elevation of Privilege Vulnerability

    Published: 15 Apr 2022
    6.5
    Medium

    CVE-2022-26911

    Last Modified: 2 Jan 2025

    Skype for Business Information Disclosure Vulnerability

    Published: 15 Apr 2022
    5.3
    Medium

    CVE-2022-26910

    Last Modified: 2 Jan 2025

    Skype for Business and Lync Spoofing Vulnerability

    Published: 15 Apr 2022
    5.3
    Medium

    CVE-2022-26907

    Last Modified: 2 Jan 2025

    Azure SDK for .NET Information Disclosure Vulnerability

    Published: 15 Apr 2022