CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2022-0450

    Last Modified: 21 Nov 2024

    The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend

    Published: 28 Mar 2022
    5.4
    Medium

    CVE-2022-0397

    Last Modified: 21 Nov 2024

    The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting

    Published: 28 Mar 2022
    4.8
    Medium

    CVE-2022-0388

    Last Modified: 21 Nov 2024

    The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-25071

    Last Modified: 21 Nov 2024

    The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2021-25070

    Last Modified: 21 Nov 2024

    The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-25068

    Last Modified: 21 Nov 2024

    The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard

    Published: 28 Mar 2022
    7.2
    High

    CVE-2021-25064

    Last Modified: 21 Nov 2024

    The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-25012

    Last Modified: 21 Nov 2024

    The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues

    Published: 28 Mar 2022
    5.3
    Medium

    CVE-2021-24978

    Last Modified: 21 Nov 2024

    The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a result, unauthenticated user can delete arbitrary posts from the blog

    Published: 28 Mar 2022
    8.8
    High

    CVE-2021-24962

    Last Modified: 21 Nov 2024

    The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code execution.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-24746

    Last Modified: 21 Nov 2024

    The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.

    Published: 28 Mar 2022
    5.5
    Medium

    CVE-2022-0221

    Last Modified: 21 Nov 2024

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)

    Published: 28 Mar 2022
    7.8
    High

    CVE-2021-22797

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)

    Published: 28 Mar 2022
    9.1
    Critical

    CVE-2021-22795

    Last Modified: 21 Nov 2024

    A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)

    Published: 28 Mar 2022
    9.1
    Critical

    CVE-2021-22794

    Last Modified: 21 Nov 2024

    A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)

    Published: 28 Mar 2022
    7.3
    High

    CVE-2019-6834

    Last Modified: 21 Nov 2024

    A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software Update (SESU) SUT Service component (V2.1.1 to V2.3.0)

    Published: 28 Mar 2022
    7.5
    High

    CVE-2021-44124

    Last Modified: 21 Nov 2024

    Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker can navigate through the device's File System over HTTP.

    Published: 28 Mar 2022
    6.6
    Medium

    CVE-2022-1015

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.

    Published: 28 Mar 2022
    5.5
    Medium

    CVE-2022-1016

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.

    Published: 28 Mar 2022
    —
    Unknown

    CVE-2021-44103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42192. Reason: This candidate is a duplicate of CVE-2021-42192. Notes: All CVE users should reference CVE-2021-42192 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-43721

    Last Modified: 21 Nov 2024

    Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-43725

    Last Modified: 21 Nov 2024

    There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-23884

    Last Modified: 21 Nov 2024

    Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-0342

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-23882

    Last Modified: 21 Nov 2024

    TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.

    Published: 28 Mar 2022
    5.3
    Medium

    CVE-2021-46434

    Last Modified: 21 Nov 2024

    EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid

    Published: 28 Mar 2022
    10
    Critical

    CVE-2021-46433

    Last Modified: 21 Nov 2024

    In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-25757

    Last Modified: 21 Nov 2024

    In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. For example, `{"string_payload":"bad","string_payload":"good"}` can be used to hide the "bad" input. Systems satisfy three conditions below are affected by this attack: 1. use body_schema validation in the request-validation plugin 2. upstream application uses a special JSON library that chooses the first occurred value, like jsoniter or gojay 3. upstream application does not validate the input anymore. The fix in APISIX is to re-encode the validated JSON input back into the request body at the side of APISIX. Improper Input Validation vulnerability in __COMPONENT__ of Apache APISIX allows an attacker to __IMPACT__. This issue affects Apache APISIX Apache APISIX version 2.12.1 and prior versions.

    Published: 28 Mar 2022
    6.5
    Medium

    CVE-2021-45491

    Last Modified: 21 Nov 2024

    3CX System through 2022-03-17 stores cleartext passwords in a database.

    Published: 28 Mar 2022
    9.1
    Critical

    CVE-2021-45490

    Last Modified: 21 Nov 2024

    The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-26273

    Last Modified: 21 Nov 2024

    EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2021-44617

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-44213

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-44212

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.

    Published: 28 Mar 2022
    5.4
    Medium

    CVE-2021-44211

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.

    Published: 28 Mar 2022
    7.5
    High

    CVE-2022-26271

    Last Modified: 21 Nov 2024

    74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-44210

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-44209

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.

    Published: 28 Mar 2022
    6.1
    Medium

    CVE-2021-44208

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.

    Published: 28 Mar 2022
    8.1
    High

    CVE-2021-26601

    Last Modified: 21 Nov 2024

    ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2021-26600

    Last Modified: 21 Nov 2024

    ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2021-26599

    Last Modified: 21 Nov 2024

    ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-26268

    Last Modified: 21 Nov 2024

    Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.

    Published: 28 Mar 2022
    5.3
    Medium

    CVE-2021-26598

    Last Modified: 21 Nov 2024

    ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).

    Published: 28 Mar 2022
    7.8
    High

    CVE-2022-26259

    Last Modified: 21 Nov 2024

    A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to cause a Denial of Service (DoS) via a crafted RSTP request.

    Published: 28 Mar 2022
    7.5
    High

    CVE-2022-1199

    Last Modified: 11 Sept 2026

    A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.

    Published: 28 Mar 2022
    6.5
    Medium

    CVE-2022-22950

    Last Modified: 21 Nov 2024

    n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

    Published: 28 Mar 2022
    8.2
    High

    CVE-2021-4207

    Last Modified: 21 Mar 2025

    A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

    Published: 28 Mar 2022
    4.4
    Medium

    CVE-2022-0216

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.

    Published: 28 Mar 2022
    5.5
    Medium

    CVE-2022-1198

    Last Modified: 21 Nov 2024

    A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.

    Published: 28 Mar 2022