CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2022-27062

    Last Modified: 21 Nov 2024

    AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.

    Published: 8 Apr 2022
    6.1
    Medium

    CVE-2022-26624

    Last Modified: 21 Nov 2024

    Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.

    Published: 8 Apr 2022
    7.2
    High

    CVE-2022-27061

    Last Modified: 21 Nov 2024

    AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 8 Apr 2022
    5.5
    Medium

    CVE-2022-27145

    Last Modified: 21 Nov 2024

    GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_movie_time of mp4box.

    Published: 8 Apr 2022
    5.5
    Medium

    CVE-2022-27147

    Last Modified: 21 Nov 2024

    GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_tag.

    Published: 8 Apr 2022
    9.1
    Critical

    CVE-2022-28805

    Last Modified: 21 Nov 2024

    singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

    Published: 8 Apr 2022
    8.8
    High

    CVE-2022-22629

    Last Modified: 22 May 2025

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Apr 2022
    7.5
    High

    CVE-2022-1278

    Last Modified: 21 Nov 2024

    A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

    Published: 8 Apr 2022
    8.8
    High

    CVE-2022-22628

    Last Modified: 22 May 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Apr 2022
    8.8
    High

    CVE-2022-22637

    Last Modified: 22 May 2025

    A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.

    Published: 8 Apr 2022
    5.7
    Medium

    CVE-2022-27152

    Last Modified: 21 Nov 2024

    Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file modification.

    Published: 8 Apr 2022
    7
    High

    CVE-2022-28796

    Last Modified: 21 Nov 2024

    jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

    Published: 8 Apr 2022
    8.8
    High

    CVE-2022-22624

    Last Modified: 22 May 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Apr 2022
    6.1
    Medium

    CVE-2022-24681

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2021-43474

    Last Modified: 21 Nov 2024

    An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2021-43453

    Last Modified: 21 Nov 2024

    A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

    Published: 7 Apr 2022
    8.4
    High

    CVE-2021-36202

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2022-26676

    Last Modified: 21 Nov 2024

    aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.

    Published: 7 Apr 2022
    7.5
    High

    CVE-2022-26675

    Last Modified: 21 Nov 2024

    aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.

    Published: 7 Apr 2022
    7.3
    High

    CVE-2022-26671

    Last Modified: 21 Nov 2024

    Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-26670

    Last Modified: 21 Nov 2024

    D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-25597

    Last Modified: 21 Nov 2024

    ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-25596

    Last Modified: 21 Nov 2024

    ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.

    Published: 7 Apr 2022
    6.5
    Medium

    CVE-2022-25595

    Last Modified: 21 Nov 2024

    ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.

    Published: 7 Apr 2022
    5.3
    Medium

    CVE-2022-25594

    Last Modified: 21 Nov 2024

    Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote attacker can input specific URLs to acquire partial system configuration information.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-23973

    Last Modified: 21 Nov 2024

    ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform arbitrary operations or disrupt service.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-23972

    Last Modified: 21 Nov 2024

    ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

    Published: 7 Apr 2022
    8.1
    High

    CVE-2022-23971

    Last Modified: 21 Nov 2024

    ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which results in service disruption.

    Published: 7 Apr 2022
    8.1
    High

    CVE-2022-23970

    Last Modified: 21 Nov 2024

    ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-0935

    Last Modified: 21 Nov 2024

    Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.

    Published: 7 Apr 2022
    7.5
    High

    CVE-2022-0677

    Last Modified: 21 Nov 2024

    Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276. Bitdefender GravityZone versions prior to 26.4-1. Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.1.111.

    Published: 7 Apr 2022
    7.5
    High

    CVE-2022-22519

    Last Modified: 21 Nov 2024

    A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.

    Published: 7 Apr 2022
    6.5
    Medium

    CVE-2022-22518

    Last Modified: 21 Nov 2024

    A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.

    Published: 7 Apr 2022
    7.5
    High

    CVE-2022-22517

    Last Modified: 21 Nov 2024

    An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

    Published: 7 Apr 2022
    7.8
    High

    CVE-2022-22516

    Last Modified: 21 Nov 2024

    The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.

    Published: 7 Apr 2022
    8.1
    High

    CVE-2022-22515

    Last Modified: 21 Nov 2024

    A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

    Published: 7 Apr 2022
    7.1
    High

    CVE-2022-22514

    Last Modified: 21 Nov 2024

    An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.

    Published: 7 Apr 2022
    6.5
    Medium

    CVE-2022-22513

    Last Modified: 21 Nov 2024

    An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.

    Published: 7 Apr 2022
    6.1
    Medium

    CVE-2021-43432

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2021-43430

    Last Modified: 21 Nov 2024

    An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.

    Published: 7 Apr 2022
    7.5
    High

    CVE-2021-43429

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2021-43421

    Last Modified: 21 Nov 2024

    A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2022-27022

    Last Modified: 21 Nov 2024

    There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.

    Published: 7 Apr 2022
    7.8
    High

    CVE-2022-1158

    Last Modified: 21 Nov 2024

    A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-26627

    Last Modified: 21 Nov 2024

    Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.

    Published: 7 Apr 2022
    5.5
    Medium

    CVE-2022-25339

    Last Modified: 26 Mar 2025

    ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2022-27016

    Last Modified: 21 Nov 2024

    There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.

    Published: 7 Apr 2022
    6.8
    Medium

    CVE-2022-25338

    Last Modified: 26 Mar 2025

    ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.

    Published: 7 Apr 2022
    9.1
    Critical

    CVE-2021-46419

    Last Modified: 21 Nov 2024

    An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

    Published: 7 Apr 2022
    7.5
    High

    CVE-2021-46418

    Last Modified: 21 Nov 2024

    An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

    Published: 7 Apr 2022