CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-22311

    Last Modified: 21 Nov 2024

    IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.

    Published: 31 Mar 2022
    9.8
    Critical

    CVE-2021-43506

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

    Published: 31 Mar 2022
    5.4
    Medium

    CVE-2021-43505

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

    Published: 31 Mar 2022
    8.8
    High

    CVE-2021-34257

    Last Modified: 21 Nov 2024

    Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.

    Published: 31 Mar 2022
    5.4
    Medium

    CVE-2022-0350

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.

    Published: 31 Mar 2022
    9.8
    Critical

    CVE-2022-24136

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.

    Published: 31 Mar 2022
    7.5
    High

    CVE-2022-1176

    Last Modified: 21 Nov 2024

    Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

    Published: 31 Mar 2022
    8.8
    High

    CVE-2022-25915

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to bypass access restriction and to access the management screen of the product via unspecified vectors.

    Published: 31 Mar 2022
    8.1
    High

    CVE-2022-1191

    Last Modified: 21 Nov 2024

    SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.

    Published: 31 Mar 2022
    7.8
    High

    CVE-2022-28128

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

    Published: 31 Mar 2022
    6.1
    Medium

    CVE-2022-27496

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Zero-channel BBS Plus v0.7.4 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 31 Mar 2022
    8.8
    High

    CVE-2022-26019

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.

    Published: 31 Mar 2022
    7.8
    High

    CVE-2022-25348

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

    Published: 31 Mar 2022
    8.8
    High

    CVE-2022-24299

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

    Published: 31 Mar 2022
    6.5
    Medium

    CVE-2022-23183

    Last Modified: 21 Nov 2024

    Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows a remote authenticated attacker to view the information on the database without the access permission.

    Published: 31 Mar 2022
    8.8
    High

    CVE-2022-22986

    Last Modified: 21 Nov 2024

    Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.

    Published: 31 Mar 2022
    6.1
    Medium

    CVE-2021-20729

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.

    Published: 31 Mar 2022
    —
    Unknown

    CVE-2021-46761

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 31 Mar 2022
    7.5
    High

    CVE-2021-43663

    Last Modified: 21 Nov 2024

    totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2021-43662

    Last Modified: 21 Nov 2024

    totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.

    Published: 30 Mar 2022
    6.1
    Medium

    CVE-2021-43661

    Last Modified: 21 Nov 2024

    totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.

    Published: 30 Mar 2022
    8.1
    High

    CVE-2021-43664

    Last Modified: 21 Nov 2024

    totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.

    Published: 30 Mar 2022
    6.1
    Medium

    CVE-2022-26644

    Last Modified: 16 Dec 2025

    Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2022-26646

    Last Modified: 16 Dec 2025

    Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2021-46006

    Last Modified: 21 Nov 2024

    In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.

    Published: 30 Mar 2022
    8.8
    High

    CVE-2022-25008

    Last Modified: 21 Nov 2024

    totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2022-26645

    Last Modified: 16 Dec 2025

    A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

    Published: 30 Mar 2022
    8.8
    High

    CVE-2021-46008

    Last Modified: 21 Nov 2024

    In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2021-46009

    Last Modified: 21 Nov 2024

    In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2021-46007

    Last Modified: 21 Nov 2024

    totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.

    Published: 30 Mar 2022
    8.8
    High

    CVE-2021-46010

    Last Modified: 21 Nov 2024

    Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.

    Published: 30 Mar 2022
    7.2
    High

    CVE-2021-33523

    Last Modified: 21 Nov 2024

    MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can execute arbitrary commands on the underlying host. This occurs in com.idsscheer.ppmmashup.business.jdbc.DriverUploadController.

    Published: 30 Mar 2022
    7.2
    High

    CVE-2021-33208

    Last Modified: 21 Nov 2024

    The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.

    Published: 30 Mar 2022
    7.2
    High

    CVE-2021-33581

    Last Modified: 21 Nov 2024

    MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2021-38362

    Last Modified: 21 Nov 2024

    In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2021-45900

    Last Modified: 21 Nov 2024

    Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper authentication. This can let an attacker impersonate as victim and make state changing requests on their behalf.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2021-43142

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2021-40645

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2021-40644

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml.

    Published: 30 Mar 2022
    7.5
    High

    CVE-2019-9564

    Last Modified: 21 Nov 2024

    A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

    Published: 30 Mar 2022
    7.6
    High

    CVE-2019-12266

    Last Modified: 21 Nov 2024

    Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

    Published: 30 Mar 2022
    7.7
    High

    CVE-2021-45031

    Last Modified: 18 May 2026

    A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate high privileged accounts passwords.

    Published: 30 Mar 2022
    6.1
    Medium

    CVE-2022-24135

    Last Modified: 21 Nov 2024

    QingScan 1.3.0 is affected by Cross Site Scripting (XSS) vulnerability in all search functions.

    Published: 30 Mar 2022
    9.1
    Critical

    CVE-2022-28223

    Last Modified: 21 Nov 2024

    Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.

    Published: 30 Mar 2022
    7.8
    High

    CVE-2022-27772

    Last Modified: 21 Nov 2024

    spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer supported by the maintainer

    Published: 30 Mar 2022
    7.5
    High

    CVE-2022-24132

    Last Modified: 21 Nov 2024

    phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.

    Published: 30 Mar 2022
    8.5
    High

    CVE-2022-22772

    Last Modified: 21 Nov 2024

    The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX and TIBCO Managed File Transfer Platform Server for z/Linux contain a difficult to exploit Remote Code Execution (RCE) vulnerability that allows a low privileged attacker with network access to execute arbitrary code on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX: versions 8.1.0 and below and TIBCO Managed File Transfer Platform Server for z/Linux: versions 8.1.0 and below.

    Published: 30 Mar 2022
    8.8
    High

    CVE-2021-44312

    Last Modified: 21 Nov 2024

    An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.

    Published: 30 Mar 2022
    4.8
    Medium

    CVE-2021-44310

    Last Modified: 21 Nov 2024

    An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored XSS attacks by inserting JavaScript and HTML code in user creation functionality.

    Published: 30 Mar 2022
    6.8
    Medium

    CVE-2021-23851

    Last Modified: 21 Nov 2024

    A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.

    Published: 30 Mar 2022