CVE Feed

    Dashboard / CVE

    5.6
    Medium

    CVE-2021-23287

    Last Modified: 21 Nov 2024

    The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70.

    Published: 1 Apr 2022
    9.8
    Critical

    CVE-2021-23247

    Last Modified: 21 Nov 2024

    A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine

    Published: 1 Apr 2022
    5.5
    Medium

    CVE-2022-1018

    Last Modified: 16 Apr 2025

    When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.

    Published: 1 Apr 2022
    6.5
    Medium

    CVE-2022-0922

    Last Modified: 16 Apr 2025

    The software does not perform any authentication for critical system functionality.

    Published: 1 Apr 2022
    7.8
    High

    CVE-2022-1098

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-33018

    Last Modified: 16 Apr 2025

    The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-33022

    Last Modified: 16 Apr 2025

    Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

    Published: 1 Apr 2022
    6.5
    Medium

    CVE-2021-27497

    Last Modified: 17 Apr 2025

    Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

    Published: 1 Apr 2022
    3.7
    Low

    CVE-2021-33024

    Last Modified: 16 Apr 2025

    Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.

    Published: 1 Apr 2022
    8.2
    High

    CVE-2021-33020

    Last Modified: 16 Apr 2025

    Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-27501

    Last Modified: 16 Apr 2025

    Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.

    Published: 1 Apr 2022
    6.1
    Medium

    CVE-2021-27493

    Last Modified: 17 Apr 2025

    Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

    Published: 1 Apr 2022
    9.8
    Critical

    CVE-2021-32976

    Last Modified: 16 Apr 2025

    Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to initiate a denial-of-service attack and execute arbitrary code.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-32970

    Last Modified: 16 Apr 2025

    Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.

    Published: 1 Apr 2022
    9.8
    Critical

    CVE-2021-32974

    Last Modified: 16 Apr 2025

    Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-32968

    Last Modified: 16 Apr 2025

    Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.

    Published: 1 Apr 2022
    8.5
    High

    CVE-2021-32960

    Last Modified: 17 Apr 2025

    Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-32945

    Last Modified: 16 Apr 2025

    An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-32949

    Last Modified: 16 Apr 2025

    An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-32957

    Last Modified: 16 Apr 2025

    A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-32937

    Last Modified: 16 Apr 2025

    An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.

    Published: 1 Apr 2022
    10
    Critical

    CVE-2021-32933

    Last Modified: 16 Apr 2025

    An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.

    Published: 1 Apr 2022
    9.8
    Critical

    CVE-2021-32953

    Last Modified: 16 Apr 2025

    An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.

    Published: 1 Apr 2022
    9.8
    Critical

    CVE-2022-27177

    Last Modified: 21 Nov 2024

    A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2

    Published: 1 Apr 2022
    7.5
    High

    CVE-2021-32961

    Last Modified: 16 Apr 2025

    A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get execution capabilities.

    Published: 1 Apr 2022
    10
    Critical

    CVE-2022-22570

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later.

    Published: 1 Apr 2022
    6.1
    Medium

    CVE-2022-21830

    Last Modified: 21 Nov 2024

    A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.

    Published: 1 Apr 2022
    —
    Unknown

    CVE-2022-27306

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 Apr 2022
    4.8
    Medium

    CVE-2022-26565

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.

    Published: 1 Apr 2022
    7.8
    High

    CVE-2022-24426

    Last Modified: 21 Nov 2024

    Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

    Published: 1 Apr 2022
    6
    Medium

    CVE-2022-23158

    Last Modified: 21 Nov 2024

    Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user with standard privilege could potentially exploit this vulnerability and provide incorrect port information and get connected to valid WMS server

    Published: 1 Apr 2022
    4.4
    Medium

    CVE-2022-23157

    Last Modified: 21 Nov 2024

    Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious user could potentially exploit this vulnerability in order to view sensitive information from the WMS Server.

    Published: 1 Apr 2022
    6
    Medium

    CVE-2022-23156

    Last Modified: 21 Nov 2024

    Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could potentially exploit this vulnerability by providing invalid input in order to obtain a connection to WMS server.

    Published: 1 Apr 2022
    7.2
    High

    CVE-2022-23155

    Last Modified: 21 Nov 2024

    Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.

    Published: 1 Apr 2022
    8.1
    High

    CVE-2022-24066

    Last Modified: 21 Nov 2024

    The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover.

    Published: 1 Apr 2022
    6.6
    Medium

    CVE-2022-1207

    Last Modified: 21 Nov 2024

    Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outside the allocated buffer boundary.

    Published: 1 Apr 2022
    8.1
    High

    CVE-2022-21223

    Last Modified: 21 Nov 2024

    The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

    Published: 1 Apr 2022
    8.1
    High

    CVE-2022-24440

    Last Modified: 21 Nov 2024

    The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

    Published: 1 Apr 2022
    6.5
    Medium

    CVE-2022-22404

    Last Modified: 21 Nov 2024

    IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulnerable to denial of service due to excessive rate limiting.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2022-22332

    Last Modified: 21 Nov 2024

    IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.

    Published: 1 Apr 2022
    7.1
    High

    CVE-2022-22331

    Last Modified: 21 Nov 2024

    IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.

    Published: 1 Apr 2022
    6.2
    Medium

    CVE-2022-22328

    Last Modified: 21 Nov 2024

    IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform unintended operations to another users data. IBM X-Force ID: 218871.

    Published: 1 Apr 2022
    7.5
    High

    CVE-2022-22327

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859.

    Published: 1 Apr 2022
    8.1
    High

    CVE-2022-21235

    Last Modified: 21 Nov 2024

    The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

    Published: 1 Apr 2022
    9.8
    Critical

    CVE-2021-44135

    Last Modified: 21 Nov 2024

    pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.

    Published: 1 Apr 2022
    6.1
    Medium

    CVE-2022-24181

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

    Published: 1 Apr 2022
    —
    Unknown

    CVE-2021-46443

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 Apr 2022
    8.8
    High

    CVE-2021-36776

    Last Modified: 21 Nov 2024

    A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.

    Published: 1 Apr 2022
    8.8
    High

    CVE-2021-36775

    Last Modified: 21 Nov 2024

    a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

    Published: 1 Apr 2022
    8.3
    High

    CVE-2022-21947

    Last Modified: 21 Nov 2024

    A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.

    Published: 1 Apr 2022