CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-23257

    Last Modified: 2 Jan 2025

    Windows Hyper-V Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.8
    High

    CVE-2022-22009

    Last Modified: 2 Jan 2025

    Windows Hyper-V Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.8
    High

    CVE-2022-22008

    Last Modified: 2 Jan 2025

    Windows Hyper-V Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.5
    High

    CVE-2022-21983

    Last Modified: 2 Jan 2025

    Win32 Stream Enumeration Remote Code Execution Vulnerability

    Published: 15 Apr 2022
    7.3
    High

    CVE-2022-24857

    Last Modified: 23 Apr 2025

    django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by modifying the regular login view. Django however has a second login view for its admin area. This second login view was not modified, so the multi factor authentication can be bypassed. Users are affected if they have activated both django-mfa3 (< 0.5.0) and django.contrib.admin and have not taken any other measures to prevent users from accessing the admin login view. The issue has been fixed in django-mfa3 0.5.0. It is possible to work around the issue by overwriting the admin login route, e.g. by adding the following URL definition *before* the admin routes: url('admin/login/', lambda request: redirect(settings.LOGIN_URL)

    Published: 15 Apr 2022
    8.1
    High

    CVE-2022-24851

    Last Modified: 22 Apr 2025

    LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated user can store XSS payloads in the profiles, which gets triggered when any other user try to access the edit profile page. The pdf editor tool has an edit pdf profile functionality, the logoFile parameter in it is not properly sanitized and an user can enter relative paths like ../../../../../../../../../../../../../usr/share/icons/hicolor/48x48/apps/gvim.png via tools like burpsuite. Later when a pdf is exported using the edited profile the pdf icon has the image on that path(if image is present). Both issues require an attacker to be able to login to LAM admin interface. The issue is fixed in version 7.9.1.

    Published: 15 Apr 2022
    7.4
    High

    CVE-2022-27048

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.

    Published: 15 Apr 2022
    7.2
    High

    CVE-2022-28113

    Last Modified: 21 Nov 2024

    An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie.

    Published: 15 Apr 2022
    9.8
    Critical

    CVE-2022-27158

    Last Modified: 21 Nov 2024

    pearweb < 1.32 suffers from Deserialization of Untrusted Data.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44507

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in str_tok in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.

    Published: 15 Apr 2022
    9.8
    Critical

    CVE-2022-27157

    Last Modified: 21 Nov 2024

    pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44510

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44509

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44508

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44506

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2022-27257

    Last Modified: 21 Nov 2024

    A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44505

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44504

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a negative value during a check. This value is then used in a memcpy call on the stack, causing a memory segmentation fault.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44503

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segmentation fault.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44502

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44501

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44500

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44499

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44498

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44497

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to be miscalculated, which leads to a use after free condition a pointer is pushed into previously free memory by the loop.

    Published: 15 Apr 2022
    9.8
    Critical

    CVE-2021-44496

    Last Modified: 21 Nov 2024

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to a call to memcpy. An attacker can use this to overwrite key data structures and gain control of the flow of execution.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44495

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44494

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44493

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.

    Published: 15 Apr 2022
    7.2
    High

    CVE-2022-27367

    Last Modified: 21 Nov 2024

    Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.

    Published: 15 Apr 2022
    7.2
    High

    CVE-2022-27369

    Last Modified: 21 Nov 2024

    Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.

    Published: 15 Apr 2022
    7.2
    High

    CVE-2022-27368

    Last Modified: 21 Nov 2024

    Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.

    Published: 15 Apr 2022
    7.2
    High

    CVE-2022-27366

    Last Modified: 21 Nov 2024

    Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.

    Published: 15 Apr 2022
    7.2
    High

    CVE-2022-27365

    Last Modified: 21 Nov 2024

    Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44492

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44491

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application. This is a digs-- calculation.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44490

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application. This is a "- (digs < 1 ? 1 : digs)" subtraction.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44489

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application. This is a "- digs" subtraction.

    Published: 15 Apr 2022
    9.1
    Critical

    CVE-2021-44488

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c in order to corrupt memory or crash the application.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44487

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

    Published: 15 Apr 2022
    9.8
    Critical

    CVE-2021-44486

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c in order to gain control of the flow of execution.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44485

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in trip_gen in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44484

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to emit_trip in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44483

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44482

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.

    Published: 15 Apr 2022
    7.5
    High

    CVE-2021-44481

    Last Modified: 21 Nov 2024

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of parameter validation in calls to memcpy in check_and_set_timeout in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.

    Published: 15 Apr 2022
    8.1
    High

    CVE-2021-36205

    Last Modified: 21 Nov 2024

    Under certain circumstances the session token is not cleared on logout.

    Published: 15 Apr 2022
    6.1
    Medium

    CVE-2022-27852

    Last Modified: 21 Nov 2024

    Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 versions.

    Published: 15 Apr 2022
    4.8
    Medium

    CVE-2021-36828

    Last Modified: 23 Apr 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions.

    Published: 15 Apr 2022
    5.4
    Medium

    CVE-2022-27851

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API key.

    Published: 15 Apr 2022