CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-26114

    Last Modified: 21 Nov 2024

    Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

    Published: 6 Apr 2022
    8.1
    High

    CVE-2021-26112

    Last Modified: 21 Nov 2024

    Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code via specifically crafted requests.

    Published: 6 Apr 2022
    9.1
    Critical

    CVE-2022-23441

    Last Modified: 21 Nov 2024

    A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2020-29013

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests.

    Published: 6 Apr 2022
    4.4
    Medium

    CVE-2022-23446

    Last Modified: 21 Nov 2024

    A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission.

    Published: 6 Apr 2022
    6.1
    Medium

    CVE-2022-1234

    Last Modified: 21 Nov 2024

    XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.

    Published: 6 Apr 2022
    7.3
    High

    CVE-2022-1248

    Last Modified: 15 Apr 2025

    A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin account for the web application with a simple POST request. Exploit details were disclosed.

    Published: 6 Apr 2022
    6.5
    Medium

    CVE-2021-40375

    Last Modified: 21 Nov 2024

    Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. This response can be read in an intercepting proxy or by viewing the page source. Sensitive information returned in responses includes patient PII and medication records or history.

    Published: 6 Apr 2022
    5.4
    Medium

    CVE-2021-40374

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes when the patient profile is loaded, which could be used in a XSS attack.

    Published: 6 Apr 2022
    7.5
    High

    CVE-2021-30497

    Last Modified: 21 Nov 2024

    Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the C:/Windows/system32/config/system.sav value.

    Published: 6 Apr 2022
    8.8
    High

    CVE-2022-26110

    Last Modified: 21 Nov 2024

    An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

    Published: 6 Apr 2022
    7.4
    High

    CVE-2021-45104

    Last Modified: 21 Nov 2024

    An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data.

    Published: 6 Apr 2022
    8.1
    High

    CVE-2021-45103

    Last Modified: 21 Nov 2024

    An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.

    Published: 6 Apr 2022
    7.5
    High

    CVE-2022-26952

    Last Modified: 21 Nov 2024

    Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page.

    Published: 6 Apr 2022
    7.5
    High

    CVE-2022-26953

    Last Modified: 21 Nov 2024

    Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an overflow when the string is concatenated to the HTML body.

    Published: 6 Apr 2022
    7.8
    High

    CVE-2022-26250

    Last Modified: 21 Nov 2024

    Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.

    Published: 6 Apr 2022
    7.2
    High

    CVE-2022-26251

    Last Modified: 21 Nov 2024

    The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

    Published: 6 Apr 2022
    9.8
    Critical

    CVE-2022-24786

    Last Modified: 23 Apr 2025

    PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.

    Published: 6 Apr 2022
    7.8
    High

    CVE-2022-1238

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

    Published: 6 Apr 2022
    9.8
    Critical

    CVE-2022-1253

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

    Published: 6 Apr 2022
    —
    Unknown

    CVE-2022-28748

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2964. Reason: This candidate is a reservation duplicate of CVE-2022-2964. Notes: All CVE users should reference CVE-2022-2964 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 6 Apr 2022
    7.8
    High

    CVE-2021-43138

    Last Modified: 21 Nov 2024

    In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.

    Published: 6 Apr 2022
    7.5
    High

    CVE-2022-1259

    Last Modified: 21 Nov 2024

    A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

    Published: 6 Apr 2022
    7.5
    High

    CVE-2022-24793

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.12 and prior affects applications that use PJSIP DNS resolution. It doesn't affect PJSIP users who utilize an external resolver. This vulnerability is related to CVE-2023-27585. The difference is that this issue is in parsing the query record `parse_rr()`, while the issue in CVE-2023-27585 is in `parse_query()`. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver instead.

    Published: 6 Apr 2022
    8.3
    High

    CVE-2022-26912

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    8.3
    High

    CVE-2022-26909

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    8.3
    High

    CVE-2022-26908

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    8.3
    High

    CVE-2022-26900

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    8.3
    High

    CVE-2022-26895

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    8.3
    High

    CVE-2022-26894

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    8.3
    High

    CVE-2022-26891

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    4.3
    Medium

    CVE-2022-24523

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 5 Apr 2022
    8.3
    High

    CVE-2022-24475

    Last Modified: 2 Jan 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 5 Apr 2022
    7.5
    High

    CVE-2022-23974

    Last Modified: 21 Nov 2024

    In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/basics/releases/0.10.0

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-28468

    Last Modified: 21 Nov 2024

    Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-28116

    Last Modified: 21 Nov 2024

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-28467

    Last Modified: 21 Nov 2024

    Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-28115

    Last Modified: 21 Nov 2024

    Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-27304

    Last Modified: 19 Sept 2025

    Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-27124

    Last Modified: 22 Apr 2025

    Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-27123

    Last Modified: 21 Nov 2024

    Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-26628

    Last Modified: 21 Nov 2024

    Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.

    Published: 5 Apr 2022
    5.4
    Medium

    CVE-2022-24811

    Last Modified: 22 Apr 2025

    Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-28219

    Last Modified: 21 Nov 2024

    Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-24780

    Last Modified: 22 Apr 2025

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.

    Published: 5 Apr 2022
    5.4
    Medium

    CVE-2022-25373

    Last Modified: 21 Nov 2024

    Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.

    Published: 5 Apr 2022
    5.3
    Medium

    CVE-2022-25245

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-24978

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-26630

    Last Modified: 21 Nov 2024

    Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php.

    Published: 5 Apr 2022
    8.4
    High

    CVE-2022-28651

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields

    Published: 5 Apr 2022