CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-1160

    Last Modified: 21 Nov 2024

    heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

    Published: 28 Mar 2022
    8.2
    High

    CVE-2021-4206

    Last Modified: 21 Mar 2025

    A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.

    Published: 28 Mar 2022
    7.5
    High

    CVE-2022-0934

    Last Modified: 3 Nov 2025

    A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.

    Published: 28 Mar 2022
    9.8
    Critical

    CVE-2022-26255

    Last Modified: 21 Nov 2024

    Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.

    Published: 27 Mar 2022
    9.8
    Critical

    CVE-2021-44127

    Last Modified: 21 Nov 2024

    In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

    Published: 27 Mar 2022
    5.3
    Medium

    CVE-2022-26254

    Last Modified: 21 Nov 2024

    WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.

    Published: 27 Mar 2022
    6.5
    Medium

    CVE-2022-26252

    Last Modified: 21 Nov 2024

    aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user private SSH key(id_rsa).

    Published: 27 Mar 2022
    9.1
    Critical

    CVE-2022-1106

    Last Modified: 21 Nov 2024

    use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

    Published: 27 Mar 2022
    9.8
    Critical

    CVE-2022-26245

    Last Modified: 21 Nov 2024

    Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.

    Published: 27 Mar 2022
    7.2
    High

    CVE-2022-27948

    Last Modified: 21 Nov 2024

    Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a fixed sequence of approximately one hundred symbols. NOTE: the vendor's perspective is that the behavior is as intended

    Published: 27 Mar 2022
    9.8
    Critical

    CVE-2022-26205

    Last Modified: 21 Nov 2024

    Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.

    Published: 27 Mar 2022
    4.3
    Medium

    CVE-2021-28544

    Last Modified: 21 Nov 2024

    Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.

    Published: 27 Mar 2022
    9.8
    Critical

    CVE-2022-26258

    Last Modified: 3 Nov 2025

    D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

    Published: 27 Mar 2022
    —
    Unknown

    CVE-2022-26620

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Mar 2022
    —
    Unknown

    CVE-2022-26200

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Mar 2022
    9.8
    Critical

    CVE-2022-26198

    Last Modified: 21 Nov 2024

    Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected into the Title text field.

    Published: 26 Mar 2022
    8.8
    High

    CVE-2022-27946

    Last Modified: 21 Nov 2024

    NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to admin_account.cgi.

    Published: 26 Mar 2022
    8.8
    High

    CVE-2022-27947

    Last Modified: 21 Nov 2024

    NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter.

    Published: 26 Mar 2022
    8.8
    High

    CVE-2022-27945

    Last Modified: 21 Nov 2024

    NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi.

    Published: 26 Mar 2022
    5.5
    Medium

    CVE-2022-27938

    Last Modified: 24 Apr 2026

    stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.

    Published: 26 Mar 2022
    5.5
    Medium

    CVE-2022-1516

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of this connection. This flaw allows a local user to crash the system.

    Published: 26 Mar 2022
    8.2
    High

    CVE-2022-1071

    Last Modified: 21 Nov 2024

    User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

    Published: 26 Mar 2022
    7.8
    High

    CVE-2022-27940

    Last Modified: 21 Nov 2024

    tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.

    Published: 26 Mar 2022
    5.5
    Medium

    CVE-2022-27939

    Last Modified: 21 Nov 2024

    tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.

    Published: 26 Mar 2022
    5.5
    Medium

    CVE-2022-27943

    Last Modified: 21 Nov 2024

    libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

    Published: 26 Mar 2022
    7.8
    High

    CVE-2022-27942

    Last Modified: 21 Nov 2024

    tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.

    Published: 26 Mar 2022
    9.1
    Critical

    CVE-2022-1587

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

    Published: 26 Mar 2022
    7.8
    High

    CVE-2022-27941

    Last Modified: 21 Nov 2024

    tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.

    Published: 26 Mar 2022
    9.8
    Critical

    CVE-2022-22274

    Last Modified: 21 Nov 2024

    A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2021-40906

    Last Modified: 21 Nov 2024

    CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.

    Published: 25 Mar 2022
    8.8
    High

    CVE-2021-40905

    Last Modified: 5 Jul 2026

    The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this manner.

    Published: 25 Mar 2022
    8.8
    High

    CVE-2021-40904

    Last Modified: 21 Nov 2024

    The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.

    Published: 25 Mar 2022
    3.7
    Low

    CVE-2022-24784

    Last Modified: 23 Apr 2025

    Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if the character is in the right position. The API has throttling enabled by default, making this a time intensive task. Both the REST API and the users endpoint need to be enabled, as they are disabled by default. The issue has been fixed in versions 3.2.39 and above, and 3.3.2 and above.

    Published: 25 Mar 2022
    10
    Critical

    CVE-2022-24783

    Last Modified: 23 Apr 2025

    Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This vulnerability does not affect users of Deno Deploy. The vulnerability has been patched in Deno 1.20.3. There is no workaround. All users are recommended to upgrade to 1.20.3 immediately.

    Published: 25 Mar 2022
    8.2
    High

    CVE-2021-44683

    Last Modified: 21 Nov 2024

    The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be exploited by tricking users into supplying sensitive information such as credentials, because the address bar would display a legitimate URL, but content would be hosted on the attacker's web site.

    Published: 25 Mar 2022
    7.1
    High

    CVE-2022-26659

    Last Modified: 21 Nov 2024

    Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.

    Published: 25 Mar 2022
    8.8
    High

    CVE-2022-25523

    Last Modified: 21 Nov 2024

    TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

    Published: 25 Mar 2022
    8.2
    High

    CVE-2021-44905

    Last Modified: 21 Nov 2024

    Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via an unauthenticated edit to the lock name.

    Published: 25 Mar 2022
    5.4
    Medium

    CVE-2022-24643

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.

    Published: 25 Mar 2022
    5.4
    Medium

    CVE-2022-26197

    Last Modified: 21 Nov 2024

    Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2022-27920

    Last Modified: 21 Nov 2024

    libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.

    Published: 25 Mar 2022
    9.8
    Critical

    CVE-2022-27919

    Last Modified: 21 Nov 2024

    Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.

    Published: 25 Mar 2022
    5.9
    Medium

    CVE-2022-27906

    Last Modified: 21 Nov 2024

    Mendelson OFTP2 before 1.1 b43 is affected by directory traversal. To access the vulnerable code path, the attacker has to know one of the configured Odette IDs of the OFTP2 server. An attacker can upload files to the server outside of the intended upload directory.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2022-27886

    Last Modified: 21 Nov 2024

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2022-27887

    Last Modified: 21 Nov 2024

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2022-27884

    Last Modified: 21 Nov 2024

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2022-27885

    Last Modified: 21 Nov 2024

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2022-26573

    Last Modified: 26 Jan 2026

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.

    Published: 25 Mar 2022
    6.5
    Medium

    CVE-2022-25590

    Last Modified: 21 Nov 2024

    SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.

    Published: 25 Mar 2022
    8.8
    High

    CVE-2022-0983

    Last Modified: 21 Nov 2024

    An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

    Published: 25 Mar 2022