CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-26338

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerPageP_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26514

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26666

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerECC.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26887

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_loopmapHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26836

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26349

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_eccoefficientHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26065

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26013

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-25880

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-0923

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26069

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-25347

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-25980

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-26059

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetQueryData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

    Published: 29 Mar 2022
    7.5
    High

    CVE-2021-44081

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2021-43701

    Last Modified: 21 Nov 2024

    CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.

    Published: 29 Mar 2022
    3.3
    Low

    CVE-2022-0343

    Last Modified: 21 Apr 2025

    A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyond 24.2

    Published: 29 Mar 2022
    5.5
    Medium

    CVE-2021-22572

    Last Modified: 21 Apr 2025

    On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive information written to theses files is visible to all other local users on unix-like systems. We recommend upgrading past commit https://github.com/google/data-transfer-project/pull/969

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28160

    Last Modified: 21 Nov 2024

    Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-28159

    Last Modified: 21 Nov 2024

    Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28158

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28157

    Last Modified: 21 Nov 2024

    Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller via FTP to an attacker-specified FTP server.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28156

    Last Modified: 21 Nov 2024

    Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the Jenkins controller to the agent workspace.

    Published: 29 Mar 2022
    8.1
    High

    CVE-2022-28155

    Last Modified: 21 Nov 2024

    Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 29 Mar 2022
    8.1
    High

    CVE-2022-28154

    Last Modified: 21 Nov 2024

    Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-28153

    Last Modified: 21 Nov 2024

    Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-28152

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to restore the default ownership of a job.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-28151

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers with Item/Read permission to change the owners and item-specific permissions of a job.

    Published: 29 Mar 2022
    8.8
    High

    CVE-2022-28150

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-28149

    Last Modified: 21 Nov 2024

    Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28148

    Last Modified: 21 Nov 2024

    The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents of arbitrary files on Windows controllers.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-28147

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28146

    Last Modified: 21 Nov 2024

    Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller by specifying an input folder on the Jenkins controller as a parameter to its build steps.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-28145

    Last Modified: 21 Nov 2024

    Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or otherwise able to control report contents.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28144

    Last Modified: 21 Nov 2024

    Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins controller JVM as part of the connection test (see CVE-2022-28142), and test a rollback with attacker-specified parameters.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28143

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins controller JVM as part of the connection test (see CVE-2022-28142), and test a rollback with attacker-specified parameters.

    Published: 29 Mar 2022
    7.5
    High

    CVE-2022-28142

    Last Modified: 21 Nov 2024

    Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28141

    Last Modified: 21 Nov 2024

    Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 29 Mar 2022
    8.1
    High

    CVE-2022-28140

    Last Modified: 21 Nov 2024

    Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-28139

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-28138

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-28137

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 29 Mar 2022
    8.8
    High

    CVE-2022-28136

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-28135

    Last Modified: 21 Nov 2024

    Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-28134

    Last Modified: 21 Nov 2024

    Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-28133

    Last Modified: 21 Nov 2024

    Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-23903

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in pearadmin pear-admin-think <=5.0.6, which allows a login account to access arbitrary functions and cause stored XSS through a fake User-Agent.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-23901

    Last Modified: 21 Nov 2024

    A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.

    Published: 29 Mar 2022
    4.8
    Medium

    CVE-2022-23059

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.

    Published: 29 Mar 2022
    7.2
    High

    CVE-2022-1032

    Last Modified: 21 Nov 2024

    Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

    Published: 29 Mar 2022