CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-43084

    Last Modified: 4 Apr 2025

    An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.

    Published: 24 Mar 2022
    7.5
    High

    CVE-2022-0153

    Last Modified: 21 Nov 2024

    SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.

    Published: 24 Mar 2022
    6.3
    Medium

    CVE-2022-21820

    Last Modified: 21 Nov 2024

    NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data confidentiality and integrity.

    Published: 24 Mar 2022
    7.5
    High

    CVE-2022-25568

    Last Modified: 21 Nov 2024

    MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

    Published: 24 Mar 2022
    9.1
    Critical

    CVE-2022-26629

    Last Modified: 21 Nov 2024

    An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

    Published: 24 Mar 2022
    4.8
    Medium

    CVE-2022-0955

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.

    Published: 24 Mar 2022
    5.4
    Medium

    CVE-2021-39491

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . .

    Published: 24 Mar 2022
    8.6
    High

    CVE-2022-0551

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

    Published: 24 Mar 2022
    8.6
    High

    CVE-2022-0550

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

    Published: 24 Mar 2022
    6.1
    Medium

    CVE-2022-1058

    Last Modified: 21 Nov 2024

    Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.

    Published: 24 Mar 2022
    5.4
    Medium

    CVE-2021-43659

    Last Modified: 21 Nov 2024

    In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.

    Published: 24 Mar 2022
    5.5
    Medium

    CVE-2022-1052

    Last Modified: 21 Nov 2024

    Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.

    Published: 24 Mar 2022
    9.8
    Critical

    CVE-2021-43700

    Last Modified: 21 Nov 2024

    An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

    Published: 24 Mar 2022
    5.4
    Medium

    CVE-2022-0145

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.

    Published: 24 Mar 2022
    7.5
    High

    CVE-2022-1061

    Last Modified: 21 Nov 2024

    Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

    Published: 24 Mar 2022
    7.5
    High

    CVE-2022-0315

    Last Modified: 21 Nov 2024

    Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.

    Published: 24 Mar 2022
    4
    Medium

    CVE-2022-27820

    Last Modified: 21 Nov 2024

    OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.

    Published: 24 Mar 2022
    7.5
    High

    CVE-2021-43666

    Last Modified: 2 Dec 2025

    A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.

    Published: 24 Mar 2022
    7
    High

    CVE-2023-4389

    Last Modified: 21 Nov 2024

    A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information.

    Published: 24 Mar 2022
    9.8
    Critical

    CVE-2022-27811

    Last Modified: 21 Nov 2024

    GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

    Published: 24 Mar 2022
    7.8
    High

    CVE-2022-1304

    Last Modified: 23 Apr 2025

    An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.

    Published: 24 Mar 2022
    7.8
    High

    CVE-2022-32546

    Last Modified: 21 Nov 2024

    A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.

    Published: 24 Mar 2022
    9.8
    Critical

    CVE-2022-27083

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-27081

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-27082

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-27080

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-27079

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-27078

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-27076

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-27077

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-26536

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-26290

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-26289

    Last Modified: 21 Nov 2024

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2021-31326

    Last Modified: 21 Nov 2024

    D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.

    Published: 23 Mar 2022
    4.3
    Medium

    CVE-2022-25266

    Last Modified: 21 Nov 2024

    Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).

    Published: 23 Mar 2022
    6.1
    Medium

    CVE-2022-25269

    Last Modified: 21 Nov 2024

    Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.

    Published: 23 Mar 2022
    8.8
    High

    CVE-2022-25268

    Last Modified: 21 Nov 2024

    Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.

    Published: 23 Mar 2022
    8.8
    High

    CVE-2022-25267

    Last Modified: 21 Nov 2024

    Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).

    Published: 23 Mar 2022
    6.5
    Medium

    CVE-2020-20096

    Last Modified: 21 Nov 2024

    Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

    Published: 23 Mar 2022
    6.5
    Medium

    CVE-2020-20095

    Last Modified: 21 Nov 2024

    iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

    Published: 23 Mar 2022
    6.5
    Medium

    CVE-2020-20094

    Last Modified: 21 Nov 2024

    Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages

    Published: 23 Mar 2022
    6.5
    Medium

    CVE-2020-20093

    Last Modified: 21 Nov 2024

    The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

    Published: 23 Mar 2022
    4.3
    Medium

    CVE-2022-25041

    Last Modified: 21 Nov 2024

    OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.

    Published: 23 Mar 2022
    7.5
    High

    CVE-2022-27192

    Last Modified: 21 Nov 2024

    The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.

    Published: 23 Mar 2022
    9.9
    Critical

    CVE-2022-24768

    Last Modified: 23 Apr 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level. Versions starting with 0.8.0 and 0.5.0 contain limited versions of this issue. To perform exploits, an authorized Argo CD user must have push access to an Application's source git or Helm repository or `sync` and `override` access to an Application. Once a user has that access, different exploitation levels are possible depending on their other RBAC privileges. A patch for this vulnerability has been released in Argo CD versions 2.3.2, 2.2.8, and 2.1.14. Some mitigation measures are available but do not serve as a substitute for upgrading. To avoid privilege escalation, limit who has push access to Application source repositories or `sync` + `override` access to Applications; and limit which repositories are available in projects where users have `update` access to Applications. To avoid unauthorized resource inspection/tampering, limit who has `delete`, `get`, or `action` access to Applications.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-24934

    Last Modified: 21 Nov 2024

    wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.

    Published: 23 Mar 2022
    7.8
    High

    CVE-2022-22819

    Last Modified: 21 Nov 2024

    NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.

    Published: 23 Mar 2022
    5.3
    Medium

    CVE-2022-27254

    Last Modified: 21 Nov 2024

    The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.

    Published: 23 Mar 2022
    7.5
    High

    CVE-2022-24757

    Last Modified: 23 Apr 2025

    The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter Server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server. Jupyter Server version 1.15.4 contains a patch for this issue. There are currently no known workarounds.

    Published: 23 Mar 2022
    9.8
    Critical

    CVE-2022-23881

    Last Modified: 21 Nov 2024

    ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

    Published: 23 Mar 2022