CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-46417

    Last Modified: 21 Nov 2024

    Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.

    Published: 7 Apr 2022
    8.1
    High

    CVE-2021-46416

    Last Modified: 13 Jul 2026

    Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2022-23900

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

    Published: 7 Apr 2022
    9.1
    Critical

    CVE-2022-27818

    Last Modified: 21 Nov 2024

    SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

    Published: 7 Apr 2022
    5.3
    Medium

    CVE-2022-27819

    Last Modified: 21 Nov 2024

    SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or infinite file (such as a block or character device).

    Published: 7 Apr 2022
    8.8
    High

    CVE-2020-27373

    Last Modified: 21 Nov 2024

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

    Published: 7 Apr 2022
    7.5
    High

    CVE-2020-27374

    Last Modified: 21 Nov 2024

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

    Published: 7 Apr 2022
    6.5
    Medium

    CVE-2020-27375

    Last Modified: 21 Nov 2024

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2020-27376

    Last Modified: 21 Nov 2024

    Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

    Published: 7 Apr 2022
    6.3
    Medium

    CVE-2022-1280

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.

    Published: 7 Apr 2022
    5.5
    Medium

    CVE-2022-1263

    Last Modified: 21 Nov 2024

    A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.

    Published: 7 Apr 2022
    8.8
    High

    CVE-2022-1271

    Last Modified: 9 Jun 2025

    An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2022-26612

    Last Modified: 21 Nov 2024

    In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry may extract an arbitrary file into the external directory using the symlink name. This however would be caught by the same targetDirPath check on Unix because of the getCanonicalPath call. However on Windows, getCanonicalPath doesn't resolve symbolic links, which bypasses the check. unpackEntries during TAR extraction follows symbolic links which allows writing outside expected base directory on Windows. This was addressed in Apache Hadoop 3.2.3

    Published: 7 Apr 2022
    9.8
    Critical

    CVE-2020-22253

    Last Modified: 21 Nov 2024

    Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device.

    Published: 6 Apr 2022
    9.8
    Critical

    CVE-2022-26613

    Last Modified: 21 Nov 2024

    PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.

    Published: 6 Apr 2022
    7.2
    High

    CVE-2022-26607

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 6 Apr 2022
    8.8
    High

    CVE-2022-26605

    Last Modified: 21 Nov 2024

    eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.

    Published: 6 Apr 2022
    7.5
    High

    CVE-2022-26591

    Last Modified: 21 Nov 2024

    FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.

    Published: 6 Apr 2022
    7.8
    High

    CVE-2022-20762

    Last Modified: 21 Nov 2024

    A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) software could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to insufficient access control in the affected CLI. An attacker could exploit this vulnerability by authenticating as a CEE ConfD CLI user and executing a specific CLI command. A successful exploit could allow an attacker to access privileged containers with root privileges.

    Published: 6 Apr 2022
    8.6
    High

    CVE-2022-20756

    Last Modified: 21 Nov 2024

    A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by attempting to authenticate to a network or a service where the access server is using Cisco ISE as the RADIUS server. A successful exploit could allow the attacker to cause Cisco ISE to stop processing RADIUS requests, causing authentication/authorization timeouts, which would then result in legitimate requests being denied access. Note: To recover the ability to process RADIUS packets, a manual restart of the affected Policy Service Node (PSN) is required. See the Details section for more information.

    Published: 6 Apr 2022
    9
    Critical

    CVE-2022-20755

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the root user. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Apr 2022
    9
    Critical

    CVE-2022-20754

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the root user. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Apr 2022
    5.3
    Medium

    CVE-2022-20675

    Last Modified: 21 Nov 2024

    A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) condition. This vulnerability is due to an open port listener on TCP port 199. An attacker could exploit this vulnerability by connecting to TCP port 199. A successful exploit could allow the attacker to crash the SNMP service, resulting in a DoS condition.

    Published: 6 Apr 2022
    6
    Medium

    CVE-2022-20665

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user. To exploit this vulnerability, an attacker would need to have valid administrative credentials on an affected device.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2022-20741

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of the Network Diagrams application for Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2022-20763

    Last Modified: 21 Nov 2024

    A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java code. This vulnerability is due to improper deserialization of Java code within login requests. An attacker could exploit this vulnerability by sending malicious login requests to the Cisco Webex Meetings service. A successful exploit could allow the attacker to inject arbitrary Java code and take arbitrary actions within the Cisco Webex Meetings application.

    Published: 6 Apr 2022
    6.8
    Medium

    CVE-2022-20774

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform configuration changes on the affected device, resulting in a denial of service (DoS) condition.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2022-20781

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.

    Published: 6 Apr 2022
    6.5
    Medium

    CVE-2022-20782

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An attacker with read-only Administrator privileges to the web-based management interface on an affected device could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.

    Published: 6 Apr 2022
    5.8
    Medium

    CVE-2022-20784

    Last Modified: 21 Nov 2024

    A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass established web request policies and access blocked content on an affected device. This vulnerability is due to incorrect handling of certain character combinations inserted into a URL. An attacker could exploit this vulnerability by sending crafted URLs to be processed by an affected device. A successful exploit could allow the attacker to bypass the web proxy and access web content that has been blocked by policy.

    Published: 6 Apr 2022
    4.3
    Medium

    CVE-2022-26850

    Last Modified: 21 Nov 2024

    When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permissions. NiFi immediately moved the temporary file to the final configuration directory, which significantly limited the window of opportunity for access. NiFi 1.16.0 includes updates to replace the Login Identity Providers configuration without writing a file to the operating system temporary directory.

    Published: 6 Apr 2022
    7.5
    High

    CVE-2022-24822

    Last Modified: 23 Apr 2025

    Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @podium/proxy is a module for proxying HTTP requests from a layout server to a podlet server. In @podium/layout prior to version 4.6.110 and @podium/proxy prior to version 4.2.74, an attacker using the `Trailer` header as part of the request against proxy endpoints has the ability to take down the server. All Podium layouts that include podlets with proxy endpoints are affected. `@podium/layout`, which is the main way developers/users are vulnerable to this exploit, has been patched in version `4.6.110`. All earlier versions are vulnerable.`@podium/proxy`, which is the source of the vulnerability and is used by `@podium/layout` has been patched in version `4.2.74`. All earlier versions are vulnerable. It is not easily possible to work around this issue without upgrading.

    Published: 6 Apr 2022
    6.2
    Medium

    CVE-2021-26113

    Last Modified: 21 Nov 2024

    A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein stored.

    Published: 6 Apr 2022
    6.7
    Medium

    CVE-2021-26116

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.

    Published: 6 Apr 2022
    7.2
    High

    CVE-2021-32585

    Last Modified: 21 Nov 2024

    An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests.

    Published: 6 Apr 2022
    7.1
    High

    CVE-2021-22127

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthenticated attacker to execute arbitrary code on the host operating system as root via tricking the user into connecting to a network with a malicious name.

    Published: 6 Apr 2022
    6.5
    Medium

    CVE-2021-41026

    Last Modified: 21 Nov 2024

    A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

    Published: 6 Apr 2022
    7.8
    High

    CVE-2021-26104

    Last Modified: 21 Nov 2024

    Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPortal 5.2.5 and below, 5.3.5 and below and 6.0.4 and below may allow a local authenticated and unprivileged user to execute arbitrary shell commands as root via specifically crafted CLI command parameters.

    Published: 6 Apr 2022
    7.2
    High

    CVE-2022-22410

    Last Modified: 21 Nov 2024

    IBM Watson Query with Cloud Pak for Data as a Service could allow an authenticated user to obtain sensitive information that would allow them to examine or alter system configurations or data sources connected to the service. IBM X-Force ID: 222763.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2022-27110

    Last Modified: 21 Nov 2024

    OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2022-27109

    Last Modified: 21 Nov 2024

    OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.

    Published: 6 Apr 2022
    4.3
    Medium

    CVE-2022-27108

    Last Modified: 21 Nov 2024

    OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2022-27107

    Last Modified: 21 Nov 2024

    OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter

    Published: 6 Apr 2022
    7.8
    High

    CVE-2022-1240

    Last Modified: 21 Nov 2024

    Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address sanitizer is disabled during the compiling, the program should executes into the `r_str_ncpy` function. Therefore I think it is very likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

    Published: 6 Apr 2022
    7.8
    High

    CVE-2022-1237

    Last Modified: 21 Nov 2024

    Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

    Published: 6 Apr 2022
    8.2
    High

    CVE-2021-44169

    Last Modified: 21 Nov 2024

    A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious executable inside the FortiClient installer's directory.

    Published: 6 Apr 2022
    7.8
    High

    CVE-2022-23440

    Last Modified: 21 Nov 2024

    A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deployment.

    Published: 6 Apr 2022
    4.3
    Medium

    CVE-2021-43205

    Last Modified: 21 Nov 2024

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.

    Published: 6 Apr 2022
    6.5
    Medium

    CVE-2021-32593

    Last Modified: 21 Nov 2024

    A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN before 4.5.9 may allow an unauthenticated remote attacker to decrypt and forge protocol communication messages.

    Published: 6 Apr 2022
    7.2
    High

    CVE-2021-24009

    Last Modified: 21 Nov 2024

    Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically crafted HTTP requests.

    Published: 6 Apr 2022