CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-3422

    Last Modified: 21 Nov 2024

    The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS or a Token, the attack requires compromising the certificate or token, or both. Implementation of either or both reduces the severity to Medium.

    Published: 25 Mar 2022
    5.3
    Medium

    CVE-2021-22100

    Last Modified: 21 Nov 2024

    In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps.

    Published: 25 Mar 2022
    9.6
    Critical

    CVE-2021-26622

    Last Modified: 21 Nov 2024

    An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this vulnerability.

    Published: 25 Mar 2022
    8.1
    High

    CVE-2021-26621

    Last Modified: 21 Nov 2024

    An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this vulnerability by using the property that the target program copies parameter values to memory through the strcpy() function.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2021-26620

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insufficient authentication when accessing the shared folder and changing user’s passwords.

    Published: 25 Mar 2022
    4.1
    Medium

    CVE-2022-25612

    Last Modified: 20 Feb 2025

    Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &custom[organiser_email], &custom[organiser_contact].

    Published: 25 Mar 2022
    4.1
    Medium

    CVE-2022-25611

    Last Modified: 20 Feb 2025

    Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][].

    Published: 25 Mar 2022
    3.4
    Low

    CVE-2022-25610

    Last Modified: 20 Feb 2025

    Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit.

    Published: 25 Mar 2022
    4.8
    Medium

    CVE-2022-25606

    Last Modified: 20 Feb 2025

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2021-44768

    Last Modified: 16 Apr 2025

    Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information.

    Published: 25 Mar 2022
    7.1
    High

    CVE-2022-0988

    Last Modified: 16 Apr 2025

    Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2021-44477

    Last Modified: 16 Apr 2025

    GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project/template file.

    Published: 25 Mar 2022
    7.8
    High

    CVE-2021-44462

    Last Modified: 16 Apr 2025

    This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, which can result in reads and writes past the end of allocated data structures. User interaction is required to exploit this vulnerability as an attacker must trick a valid user to open a malicious HMI project file.

    Published: 25 Mar 2022
    8.2
    High

    CVE-2021-35254

    Last Modified: 21 Nov 2024

    SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.

    Published: 25 Mar 2022
    9.8
    Critical

    CVE-2021-43636

    Last Modified: 21 Nov 2024

    Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing host data in the HTTP request process.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2022-27882

    Last Modified: 21 Nov 2024

    slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2022-27881

    Last Modified: 21 Nov 2024

    engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2022-26263

    Last Modified: 21 Nov 2024

    Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

    Published: 25 Mar 2022
    5.4
    Medium

    CVE-2022-25582

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2022-24777

    Last Modified: 23 Apr 2025

    grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when handling GOAWAY frames. The attack is low-effort: it takes very little resources to construct and send the required sequence of frames. The impact on availability is high as the server will crash, dropping all in flight connections and requests. This issue is fixed in version 1.7.2. There are currently no known workarounds.

    Published: 25 Mar 2022
    9.1
    Critical

    CVE-2022-25577

    Last Modified: 21 Nov 2024

    ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are able to gain remote or local access to the system are able to read and modify the data.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2021-43091

    Last Modified: 21 Nov 2024

    An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form.

    Published: 25 Mar 2022
    4.8
    Medium

    CVE-2022-25574

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.

    Published: 25 Mar 2022
    6.1
    Medium

    CVE-2021-46426

    Last Modified: 21 Nov 2024

    phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

    Published: 25 Mar 2022
    9.8
    Critical

    CVE-2021-43090

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.

    Published: 25 Mar 2022
    8.1
    High

    CVE-2020-21554

    Last Modified: 21 Nov 2024

    A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2022-27227

    Last Modified: 21 Nov 2024

    In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.

    Published: 25 Mar 2022
    9.8
    Critical

    CVE-2022-1040

    Last Modified: 27 Oct 2025

    An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

    Published: 25 Mar 2022
    8.8
    High

    CVE-2022-1064

    Last Modified: 21 Nov 2024

    SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.

    Published: 25 Mar 2022
    4.3
    Medium

    CVE-2021-44751

    Last Modified: 21 Nov 2024

    A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS, dialer application will require user interaction, however, some older Android OS may not need user interaction.

    Published: 25 Mar 2022
    9.8
    Critical

    CVE-2022-22687

    Last Modified: 14 Jan 2025

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 25 Mar 2022
    8.8
    High

    CVE-2022-22688

    Last Modified: 14 Jan 2025

    Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

    Published: 25 Mar 2022
    —
    Unknown

    CVE-2022-27915

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 25 Mar 2022
    —
    Unknown

    CVE-2022-27916

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 25 Mar 2022
    —
    Unknown

    CVE-2022-27917

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 25 Mar 2022
    —
    Unknown

    CVE-2022-27918

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 25 Mar 2022
    7.5
    High

    CVE-2022-24778

    Last Modified: 22 Apr 2025

    The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt function `CheckAuthorization` is supposed to check whether the current used is authorized to access an encrypted image and prevent the user from running an image that another user previously decrypted on the same system. In versions prior to 1.1.4, a failure occurs when an image with a ManifestList is used and the architecture of the local host is not the first one in the ManifestList. Only the first architecture in the list was tested, which may not have its layers available locally since it could not be run on the host architecture. Therefore, the verdict on unavailable layers was that the image could be run anticipating that image run failure would occur later due to the layers not being available. However, this verdict to allow the image to run enabled other architectures in the ManifestList to run an image without providing keys if that image had previously been decrypted. A patch has been applied to imgcrypt 1.1.4. Workarounds may include usage of different namespaces for each remote user.

    Published: 25 Mar 2022
    10
    Critical

    CVE-2022-22995

    Last Modified: 3 Nov 2025

    The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

    Published: 25 Mar 2022
    5.5
    Medium

    CVE-2022-2153

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.

    Published: 25 Mar 2022
    4.5
    Medium

    CVE-2022-25576

    Last Modified: 21 Nov 2024

    Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.

    Published: 24 Mar 2022
    9.8
    Critical

    CVE-2022-26279

    Last Modified: 21 Nov 2024

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

    Published: 24 Mar 2022
    9.8
    Critical

    CVE-2022-26272

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php.

    Published: 24 Mar 2022
    6.1
    Medium

    CVE-2022-25575

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification code text boxes.

    Published: 24 Mar 2022
    9.8
    Critical

    CVE-2022-26301

    Last Modified: 21 Nov 2024

    TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.

    Published: 24 Mar 2022
    9.8
    Critical

    CVE-2022-26249

    Last Modified: 21 Nov 2024

    Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.

    Published: 24 Mar 2022
    4.3
    Medium

    CVE-2022-24782

    Last Modified: 23 Apr 2025

    Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior in the `beta` branch, and 2.9.0.beta3 and prior in the `tests-passed` branch are vulnerable to a data leak. Users can request an export of their own activity. Sometimes, due to category settings, they may have category membership for a secure category. The name of this secure category is shown to the user in the export. The same thing occurs when the user's post has been moved to a secure category. A patch for this issue is available in the `main` branch of Discourse's GitHub repository and is anticipated to be part of future releases.

    Published: 24 Mar 2022
    7.1
    High

    CVE-2022-24781

    Last Modified: 23 Apr 2025

    Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session. This issue is patched in version 1.1.0. No known workaround exists.

    Published: 24 Mar 2022
    7.5
    High

    CVE-2022-25571

    Last Modified: 21 Nov 2024

    Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information leak which allows attackers to access the contents of the password file via unspecified vectors.

    Published: 24 Mar 2022
    6.1
    Medium

    CVE-2022-24776

    Last Modified: 23 Apr 2025

    Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are currently no known workarounds.

    Published: 24 Mar 2022
    9.1
    Critical

    CVE-2022-22374

    Last Modified: 21 Nov 2024

    The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its host. IBM X-Force ID: 221442.

    Published: 24 Mar 2022