CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2022-28650

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

    Published: 5 Apr 2022
    4.6
    Medium

    CVE-2022-28649

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

    Published: 5 Apr 2022
    5.7
    Medium

    CVE-2022-28648

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered

    Published: 5 Apr 2022
    5.5
    Medium

    CVE-2022-1244

    Last Modified: 21 Nov 2024

    heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-26635

    Last Modified: 21 Nov 2024

    PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-22356

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487.

    Published: 5 Apr 2022
    5.3
    Medium

    CVE-2022-22355

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.

    Published: 5 Apr 2022
    5.4
    Medium

    CVE-2022-0602

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2021-41752

    Last Modified: 21 Nov 2024

    Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recursive call to the new opt() function.

    Published: 5 Apr 2022
    6.1
    Medium

    CVE-2022-27463

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2020-19229

    Last Modified: 21 Nov 2024

    Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2021-28428

    Last Modified: 21 Nov 2024

    File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading an arbitrary .htaccess and *.hello files in order to execute PHP code to gain RCE.

    Published: 5 Apr 2022
    5.4
    Medium

    CVE-2020-28847

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment.

    Published: 5 Apr 2022
    6.1
    Medium

    CVE-2022-27462

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2021-41751

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2021-30080

    Last Modified: 21 Nov 2024

    An issue was discovered in the route lookup process in beego before 1.12.11 that allows attackers to bypass access control.

    Published: 5 Apr 2022
    7.8
    High

    CVE-2021-27116

    Last Modified: 21 Nov 2024

    An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally.

    Published: 5 Apr 2022
    7.8
    High

    CVE-2021-27117

    Last Modified: 21 Nov 2024

    An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink attacks locally.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2020-23349

    Last Modified: 21 Nov 2024

    An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivity), any unexported Activities could be started by the com.sina.weibo.sdk.share.WbShareTransActivity.

    Published: 5 Apr 2022
    7.1
    High

    CVE-2022-41858

    Last Modified: 7 Apr 2025

    A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.

    Published: 5 Apr 2022
    —
    Unknown

    CVE-2022-27876

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Apr 2022
    —
    Unknown

    CVE-2022-28694

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Apr 2022
    —
    Unknown

    CVE-2022-28698

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Apr 2022
    —
    Unknown

    CVE-2022-26515

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Apr 2022
    —
    Unknown

    CVE-2022-25868

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Apr 2022
    —
    Unknown

    CVE-2022-27173

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 5 Apr 2022
    6.1
    Medium

    CVE-2022-1243

    Last Modified: 21 Nov 2024

    CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2021-41245

    Last Modified: 22 Apr 2025

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2021-38834

    Last Modified: 21 Nov 2024

    easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special js code.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-1236

    Last Modified: 21 Nov 2024

    Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.

    Published: 5 Apr 2022
    8.2
    High

    CVE-2022-1235

    Last Modified: 21 Nov 2024

    Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.

    Published: 5 Apr 2022
    7.3
    High

    CVE-2022-25154

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows 7, 10, or 11 to exploit this vulnerability.)

    Published: 5 Apr 2022
    7.8
    High

    CVE-2022-23909

    Last Modified: 21 Nov 2024

    There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2021-39114

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-1212

    Last Modified: 21 Nov 2024

    Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

    Published: 5 Apr 2022
    8.1
    High

    CVE-2022-1213

    Last Modified: 21 Nov 2024

    SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2021-33207

    Last Modified: 21 Nov 2024

    The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570 status code.

    Published: 5 Apr 2022
    5.3
    Medium

    CVE-2022-25356

    Last Modified: 5 Sept 2025

    Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2022-26281

    Last Modified: 21 Nov 2024

    BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2021-43008

    Last Modified: 21 Nov 2024

    Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2021-45891

    Last Modified: 21 Nov 2024

    An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all permission checks are done client-side, not server-side.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2021-44109

    Last Modified: 21 Nov 2024

    A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2021-44108

    Last Modified: 21 Nov 2024

    A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.

    Published: 5 Apr 2022
    5.4
    Medium

    CVE-2022-26615

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-24231

    Last Modified: 21 Nov 2024

    Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student.

    Published: 5 Apr 2022
    5.9
    Medium

    CVE-2021-45892

    Last Modified: 21 Nov 2024

    An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2021-45893

    Last Modified: 21 Nov 2024

    An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes password guessing easier.

    Published: 5 Apr 2022
    7.4
    High

    CVE-2021-42324

    Last Modified: 21 Nov 2024

    An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.

    Published: 5 Apr 2022
    5.9
    Medium

    CVE-2021-45894

    Last Modified: 21 Nov 2024

    An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2022-25584

    Last Modified: 21 Nov 2024

    Seyeon Tech Co., Ltd FlexWATCH FW3170-PS-E Network Video System 4.23-3000_GY allows attackers to access sensitive information.

    Published: 5 Apr 2022