CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-27649

    Last Modified: 21 Nov 2024

    A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

    Published: 30 Mar 2022
    7.5
    High

    CVE-2022-27650

    Last Modified: 21 Nov 2024

    A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

    Published: 30 Mar 2022
    5.3
    Medium

    CVE-2022-27652

    Last Modified: 21 Nov 2024

    A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

    Published: 30 Mar 2022
    6.1
    Medium

    CVE-2022-24131

    Last Modified: 21 Nov 2024

    DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.

    Published: 30 Mar 2022
    5.4
    Medium

    CVE-2022-1179

    Last Modified: 21 Nov 2024

    Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

    Published: 30 Mar 2022
    3.5
    Low

    CVE-2022-1180

    Last Modified: 21 Nov 2024

    Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

    Published: 30 Mar 2022
    5.4
    Medium

    CVE-2022-1181

    Last Modified: 21 Nov 2024

    Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.

    Published: 30 Mar 2022
    4.3
    Medium

    CVE-2022-1177

    Last Modified: 21 Nov 2024

    Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.

    Published: 30 Mar 2022
    5.4
    Medium

    CVE-2022-1178

    Last Modified: 21 Nov 2024

    Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2022-23869

    Last Modified: 21 Nov 2024

    In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

    Published: 30 Mar 2022
    7.8
    High

    CVE-2022-23868

    Last Modified: 21 Nov 2024

    RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.

    Published: 30 Mar 2022
    5
    Medium

    CVE-2022-1172

    Last Modified: 21 Nov 2024

    Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

    Published: 30 Mar 2022
    7.1
    High

    CVE-2022-1671

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.

    Published: 30 Mar 2022
    7.5
    High

    CVE-2022-25598

    Last Modified: 21 Nov 2024

    Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

    Published: 30 Mar 2022
    4.8
    Medium

    CVE-2022-1163

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.

    Published: 30 Mar 2022
    7.1
    High

    CVE-2022-27816

    Last Modified: 21 Nov 2024

    SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2022-24693

    Last Modified: 21 Nov 2024

    Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2020-24769

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2020-24770

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Mar 2022
    7.5
    High

    CVE-2020-24771

    Last Modified: 21 Nov 2024

    Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2022-22965

    Last Modified: 30 Oct 2025

    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

    Published: 30 Mar 2022
    7.5
    High

    CVE-2022-24763

    Last Modified: 6 May 2026

    PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.

    Published: 30 Mar 2022
    7.8
    High

    CVE-2022-1154

    Last Modified: 21 Nov 2024

    Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2022-28205

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2022-28206

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights.

    Published: 30 Mar 2022
    9.8
    Critical

    CVE-2022-28209

    Last Modified: 21 Nov 2024

    An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect.

    Published: 30 Mar 2022
    9.1
    Critical

    CVE-2022-24790

    Last Modified: 23 Apr 2025

    Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may disagree on where a request starts and ends. This would allow requests to be smuggled via the front-end proxy to Puma. The vulnerability has been fixed in 5.6.4 and 4.3.12. Users are advised to upgrade as soon as possible. Workaround: when deploying a proxy in front of Puma, turning on any and all functionality to make sure that the request matches the RFC7230 standard.

    Published: 30 Mar 2022
    6.1
    Medium

    CVE-2022-28202

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.

    Published: 30 Mar 2022
    6.5
    Medium

    CVE-2021-41594

    Last Modified: 21 Nov 2024

    In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-26951

    Last Modified: 21 Nov 2024

    Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-26950

    Last Modified: 21 Nov 2024

    Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.

    Published: 29 Mar 2022
    5.3
    Medium

    CVE-2022-26949

    Last Modified: 21 Nov 2024

    Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowed by extra privileges.

    Published: 29 Mar 2022
    5.8
    Medium

    CVE-2022-26948

    Last Modified: 21 Nov 2024

    The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.

    Published: 29 Mar 2022
    6.3
    Medium

    CVE-2022-26947

    Last Modified: 21 Nov 2024

    Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.

    Published: 29 Mar 2022
    8.8
    High

    CVE-2022-27432

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

    Published: 29 Mar 2022
    7.8
    High

    CVE-2022-27815

    Last Modified: 21 Nov 2024

    SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.

    Published: 29 Mar 2022
    8.8
    High

    CVE-2015-3298

    Last Modified: 21 Nov 2024

    Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-26244

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.

    Published: 29 Mar 2022
    8.3
    High

    CVE-2021-44082

    Last Modified: 21 Nov 2024

    textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26871

    Last Modified: 22 Dec 2025

    An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

    Published: 29 Mar 2022
    7.8
    High

    CVE-2022-21821

    Last Modified: 21 Nov 2024

    NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2021-43118

    Last Modified: 21 Nov 2024

    A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2021-42911

    Last Modified: 21 Nov 2024

    A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2021-43110

    Last Modified: 21 Nov 2024

    An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.

    Published: 29 Mar 2022
    7.5
    High

    CVE-2021-43109

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-22948

    Last Modified: 31 Oct 2025

    The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

    Published: 29 Mar 2022
    6.1
    Medium

    CVE-2021-42970

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-27175

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    7.8
    High

    CVE-2022-26839

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26667

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022