CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-27273

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.

    Published: 10 Apr 2022
    9.8
    Critical

    CVE-2022-27272

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.

    Published: 10 Apr 2022
    9.8
    Critical

    CVE-2022-27274

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.

    Published: 10 Apr 2022
    9.8
    Critical

    CVE-2022-27275

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.

    Published: 10 Apr 2022
    9.1
    Critical

    CVE-2022-27277

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.

    Published: 10 Apr 2022
    9.8
    Critical

    CVE-2022-27276

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27279

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0.

    Published: 10 Apr 2022
    5.4
    Medium

    CVE-2022-27280

    Last Modified: 21 Nov 2024

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the web_exec parameter at /apply.cgi.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27286

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27287

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27288

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27289

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27290

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27291

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27292

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27293

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27294

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

    Published: 10 Apr 2022
    7.5
    High

    CVE-2022-27295

    Last Modified: 21 Nov 2024

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

    Published: 10 Apr 2022
    5.4
    Medium

    CVE-2022-1291

    Last Modified: 21 Nov 2024

    XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. Transmitting cookies to third-party servers. Sending data from secure sessions to third-party servers

    Published: 10 Apr 2022
    5.4
    Medium

    CVE-2022-1290

    Last Modified: 21 Nov 2024

    Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

    Published: 10 Apr 2022
    4.3
    Medium

    CVE-2022-1289

    Last Modified: 15 Apr 2025

    A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. The issue got fixed with the patch 0eb02422d5161767e9983bdaa5c429762d3477ce.

    Published: 10 Apr 2022
    9.8
    Critical

    CVE-2022-1286

    Last Modified: 21 Nov 2024

    heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

    Published: 10 Apr 2022
    9.8
    Critical

    CVE-2022-1276

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

    Published: 10 Apr 2022
    4.3
    Medium

    CVE-2022-1288

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue affects access to /scas/admin/. The manipulation of the parameter page with the input %22%3E%3Cimg%20src=x%20onerror=alert(1)%3E leads to a reflected cross site scripting. The attack may be initiated remotely and does not require any form of authentication. The exploit has been disclosed to the public and may be used.

    Published: 9 Apr 2022
    6.5
    Medium

    CVE-2022-1287

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The manipulation with a POST request leads to privilege escalation. The attack can be initiated remotely and does not require authentication. The exploit has been disclosed to the public and may be used.

    Published: 9 Apr 2022
    5.4
    Medium

    CVE-2022-28364

    Last Modified: 30 Apr 2025

    Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.

    Published: 9 Apr 2022
    6.1
    Medium

    CVE-2022-28363

    Last Modified: 30 Apr 2025

    Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.

    Published: 9 Apr 2022
    6.7
    Medium

    CVE-2023-3159

    Last Modified: 23 Apr 2025

    A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.

    Published: 9 Apr 2022
    —
    Unknown

    CVE-2022-27149

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Apr 2022
    6.5
    Medium

    CVE-2022-26877

    Last Modified: 21 Nov 2024

    Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page.

    Published: 9 Apr 2022
    7.3
    High

    CVE-2022-27883

    Last Modified: 21 Nov 2024

    A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to exploit this vulnerability.

    Published: 9 Apr 2022
    5.3
    Medium

    CVE-2022-28365

    Last Modified: 30 Apr 2025

    Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.

    Published: 9 Apr 2022
    7.8
    High

    CVE-2022-32547

    Last Modified: 21 Nov 2024

    In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.

    Published: 9 Apr 2022
    6.5
    Medium

    CVE-2022-26588

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.

    Published: 8 Apr 2022
    8.8
    High

    CVE-2022-26180

    Last Modified: 21 Nov 2024

    qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

    Published: 8 Apr 2022
    —
    Unknown

    CVE-2021-43149

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 8 Apr 2022
    6.1
    Medium

    CVE-2021-43009

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.

    Published: 8 Apr 2022
    5.5
    Medium

    CVE-2022-26855

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability, leading to a denial of service.

    Published: 8 Apr 2022
    8.1
    High

    CVE-2022-26854

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access

    Published: 8 Apr 2022
    8.1
    High

    CVE-2022-26852

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise.

    Published: 8 Apr 2022
    9.1
    Critical

    CVE-2022-26851

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.

    Published: 8 Apr 2022
    6.3
    Medium

    CVE-2022-24428

    Last Modified: 21 Nov 2024

    Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure.

    Published: 8 Apr 2022
    4.4
    Medium

    CVE-2022-22563

    Last Modified: 21 Nov 2024

    Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.

    Published: 8 Apr 2022
    6.4
    Medium

    CVE-2021-36293

    Last Modified: 21 Nov 2024

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.

    Published: 8 Apr 2022
    6.4
    Medium

    CVE-2021-36290

    Last Modified: 21 Nov 2024

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain privileges.

    Published: 8 Apr 2022
    8.6
    High

    CVE-2021-36288

    Last Modified: 21 Nov 2024

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files

    Published: 8 Apr 2022
    7.3
    High

    CVE-2021-36287

    Last Modified: 21 Nov 2024

    Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.

    Published: 8 Apr 2022
    5.3
    Medium

    CVE-2022-24820

    Last Modified: 22 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

    Published: 8 Apr 2022
    5.3
    Medium

    CVE-2022-24819

    Last Modified: 22 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

    Published: 8 Apr 2022
    6.8
    Medium

    CVE-2022-24821

    Last Modified: 22 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.

    Published: 8 Apr 2022