CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2021-46743

    Last Modified: 21 Nov 2024

    In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a straightforward way to use the PHP-JWT library unsafely, but might not be considered a vulnerability in the library itself.

    Published: 29 Mar 2022
    3.5
    Low

    CVE-2022-1087

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profile Module. The manipulation of the field Title with script tags leads to persistent cross site scripting. The attack may be initiated remotely and requires an authentication. A simple POC has been disclosed to the public and may be used.

    Published: 29 Mar 2022
    3.5
    Low

    CVE-2022-1086

    Last Modified: 15 Apr 2025

    A vulnerability was found in DolphinPHP up to 1.5.0 and classified as problematic. Affected by this issue is the User Management Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Mar 2022
    3.5
    Low

    CVE-2022-1085

    Last Modified: 15 Apr 2025

    A vulnerability was found in CLTPHP up to 6.0. It has been declared as problematic. Affected by this vulnerability is the POST Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Mar 2022
    7.3
    High

    CVE-2022-1084

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched remotely.

    Published: 29 Mar 2022
    7.3
    High

    CVE-2022-1083

    Last Modified: 15 Apr 2025

    A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc leads to sql injection in multiple files. It is possible to launch the attack remotely.

    Published: 29 Mar 2022
    7.3
    High

    CVE-2022-1082

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/password with the input '||1=1# leads to sql injection. The attack may be initiated remotely.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-1081

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been declared as problematic. This vulnerability affects the file /mims/app/addcustomerHandler.php. The manipulation of the argument first_name, middle_name, and surname leads to cross site scripting. The attack can be initiated remotely.

    Published: 29 Mar 2022
    7.3
    High

    CVE-2022-1080

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads to sql injection. The attack can be initiated remotely.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-1079

    Last Modified: 15 Apr 2025

    A vulnerability classified as problematic has been found in SourceCodester One Church Management System. Affected are multiple files and parameters which are prone to to cross site scripting. It is possible to launch the attack remotely.

    Published: 29 Mar 2022
    7.3
    High

    CVE-2022-1078

    Last Modified: 15 Apr 2025

    A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.

    Published: 29 Mar 2022
    5.3
    Medium

    CVE-2022-1077

    Last Modified: 15 Apr 2025

    A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware information. The attack can be initiated remotely and does not require any form of authentication.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-1076

    Last Modified: 15 Apr 2025

    A vulnerability was found in Automatic Question Paper Generator System 1.0. It has been classified as problematic. This affects the file /aqpg/users/login.php of the component My Account Page. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely.

    Published: 29 Mar 2022
    3.5
    Low

    CVE-2022-1075

    Last Modified: 15 Apr 2025

    A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication.

    Published: 29 Mar 2022
    4.3
    Medium

    CVE-2022-1074

    Last Modified: 15 Apr 2025

    A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of the dashboard leads to html injection.

    Published: 29 Mar 2022
    7.3
    High

    CVE-2022-1073

    Last Modified: 15 Apr 2025

    A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.

    Published: 29 Mar 2022
    —
    Unknown

    CVE-2022-1072

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26254. Reason: This candidate is a reservation duplicate of CVE-2022-26254. Notes: All CVE users should reference CVE-2022-26254 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Mar 2022
    5.3
    Medium

    CVE-2022-23937

    Last Modified: 21 Nov 2024

    In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2022-24957

    Last Modified: 21 Nov 2024

    DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability, the attacker has to create or edit a new information object and use the XSS payload as the name. Any user that opens the object's version or history tab will be attacked.

    Published: 29 Mar 2022
    6.5
    Medium

    CVE-2022-24956

    Last Modified: 21 Nov 2024

    An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-25420

    Last Modified: 21 Nov 2024

    NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.

    Published: 29 Mar 2022
    7.5
    High

    CVE-2021-44581

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2021-45865

    Last Modified: 21 Nov 2024

    A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.

    Published: 29 Mar 2022
    5.4
    Medium

    CVE-2021-45866

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via the couse filed in index.php.

    Published: 29 Mar 2022
    4.6
    Medium

    CVE-2022-26269

    Last Modified: 21 Nov 2024

    Suzuki Connect v1.0.15 allows attackers to tamper with displayed messages via spoofed CAN messages.

    Published: 29 Mar 2022
    5.3
    Medium

    CVE-2022-0331

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-25521

    Last Modified: 4 Jul 2026

    NUUO v03.11.00 was discovered to contain access control issue.

    Published: 29 Mar 2022
    9.8
    Critical

    CVE-2022-22963

    Last Modified: 30 Oct 2025

    In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

    Published: 29 Mar 2022
    8.8
    High

    CVE-2022-22934

    Last Modified: 21 Nov 2024

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.

    Published: 29 Mar 2022
    3.7
    Low

    CVE-2022-22935

    Last Modified: 5 May 2025

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.

    Published: 29 Mar 2022
    8.8
    High

    CVE-2022-22941

    Last Modified: 5 May 2025

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no valid targets as valid, allowing configured users to target any of the minions connected to the syndic with their configured commands. This requires a syndic master combined with publisher_acl configured on the Master-of-Masters, allowing users specified in the publisher_acl to bypass permissions, publishing authorized commands to any configured minion.

    Published: 29 Mar 2022
    8.8
    High

    CVE-2022-22936

    Last Modified: 5 May 2025

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be re-played. A sufficient craft attacker could gain root access on minion under certain scenarios.

    Published: 29 Mar 2022
    5.5
    Medium

    CVE-2022-26296

    Last Modified: 21 Nov 2024

    BOOM: The Berkeley Out-of-Order RISC-V Processor commit d77c2c3 was discovered to allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2022-26641

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2022-26642

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2022-26639

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2022-26640

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.

    Published: 28 Mar 2022
    4.3
    Medium

    CVE-2021-43105

    Last Modified: 21 Nov 2024

    A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific malicious users to inject `NS` records of any domain (even TLDs) into the cache and conduct a DNS cache poisoning attack.

    Published: 28 Mar 2022
    5.5
    Medium

    CVE-2022-26291

    Last Modified: 21 Nov 2024

    lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.

    Published: 28 Mar 2022
    7.6
    High

    CVE-2022-24789

    Last Modified: 23 Apr 2025

    C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The attacker may also truncate arbitrary files to zero size (effectively delete them) leading to denial of service (DoS) or altering application logic. The authenticated user may unknowingly perform the actions by visiting a specially crafted site. Patched in C1 CMS v6.12, no known workarounds exist.

    Published: 28 Mar 2022
    6.5
    Medium

    CVE-2022-26280

    Last Modified: 3 Nov 2025

    Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-43103

    Last Modified: 21 Nov 2024

    A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-43102

    Last Modified: 21 Nov 2024

    A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-43101

    Last Modified: 21 Nov 2024

    A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-43100

    Last Modified: 21 Nov 2024

    A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

    Published: 28 Mar 2022
    4.9
    Medium

    CVE-2021-43099

    Last Modified: 21 Nov 2024

    An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.java, which unzips the arbitrary upladed zip file without checking filenames. The vulnerability is exploited using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe).

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-43098

    Last Modified: 21 Nov 2024

    A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-43097

    Last Modified: 21 Nov 2024

    A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-26278

    Last Modified: 21 Nov 2024

    Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

    Published: 28 Mar 2022
    4.3
    Medium

    CVE-2017-20016

    Last Modified: 21 Nov 2024

    A vulnerability has been found in WEKA INTEREST Security Scanner up to 1.8 and classified as problematic. This vulnerability affects unknown code of the component Portscan. The manipulation with an unknown input leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 28 Mar 2022