CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-45756

    Last Modified: 21 Nov 2024

    Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.

    Published: 23 Mar 2022
    6.7
    Medium

    CVE-2022-20153

    Last Modified: 21 Nov 2024

    In rcu_cblist_dequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222091980References: Upstream kernel

    Published: 23 Mar 2022
    7
    High

    CVE-2022-1048

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published: 23 Mar 2022
    7.8
    High

    CVE-2022-1033

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

    Published: 23 Mar 2022
    5.5
    Medium

    CVE-2021-28275

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

    Published: 23 Mar 2022
    7.5
    High

    CVE-2021-28276

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.

    Published: 23 Mar 2022
    7.8
    High

    CVE-2021-28277

    Last Modified: 21 Nov 2024

    A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.

    Published: 23 Mar 2022
    7.8
    High

    CVE-2021-28278

    Last Modified: 21 Nov 2024

    A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.

    Published: 23 Mar 2022
    7.3
    High

    CVE-2021-44226

    Last Modified: 21 Nov 2024

    Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse DLLs there.

    Published: 23 Mar 2022
    9.1
    Critical

    CVE-2022-0567

    Last Modified: 21 Nov 2024

    A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.

    Published: 23 Mar 2022
    —
    Unknown

    CVE-2022-27675

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 23 Mar 2022
    —
    Unknown

    CVE-2022-27676

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 23 Mar 2022
    9.1
    Critical

    CVE-2022-1586

    Last Modified: 25 Mar 2025

    An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.

    Published: 23 Mar 2022
    5.9
    Medium

    CVE-2022-24769

    Last Modified: 21 Nov 2024

    Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during `execve(2)`. Normally, when executable programs have specified permitted file capabilities, otherwise unprivileged users and processes can execute those programs and gain the specified file capabilities up to the bounding set. Due to this bug, containers which included executable programs with inheritable file capabilities allowed otherwise unprivileged users and processes to additionally gain these inheritable file capabilities up to the container's bounding set. Containers which use Linux users and groups to perform privilege separation inside the container are most directly impacted. This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in Moby (Docker Engine) 20.10.14. Running containers should be stopped, deleted, and recreated for the inheritable capabilities to be reset. This fix changes Moby (Docker Engine) behavior such that containers are started with a more typical Linux environment. As a workaround, the entry point of a container can be modified to use a utility like `capsh(1)` to drop inheritable capabilities prior to the primary process starting.

    Published: 23 Mar 2022
    6.5
    Medium

    CVE-2022-25518

    Last Modified: 21 Nov 2024

    In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the password of the users who login to the application by querying the database table.

    Published: 22 Mar 2022
    6.1
    Medium

    CVE-2021-33961

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2022-26189

    Last Modified: 21 Nov 2024

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2022-26188

    Last Modified: 21 Nov 2024

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2022-26187

    Last Modified: 21 Nov 2024

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2022-26186

    Last Modified: 21 Nov 2024

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.

    Published: 22 Mar 2022
    7.8
    High

    CVE-2022-1031

    Last Modified: 21 Nov 2024

    Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2022-26260

    Last Modified: 21 Nov 2024

    Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2022-27228

    Last Modified: 21 Nov 2024

    In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2021-41736

    Last Modified: 21 Nov 2024

    Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp.

    Published: 22 Mar 2022
    8.8
    High

    CVE-2022-1025

    Last Modified: 21 Nov 2024

    All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.

    Published: 22 Mar 2022
    7.7
    High

    CVE-2022-24730

    Last Modified: 23 Apr 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with read-only repository access to leak sensitive files from Argo CD's repo-server. A malicious Argo CD user who has been granted `get` access for a repository containing a Helm chart can craft an API request to the `/api/v1/repositories/{repo_url}/appdetails` endpoint to leak the contents of out-of-bounds files from the repo-server. The malicious payload would reference an out-of-bounds file, and the contents of that file would be returned as part of the response. Contents from a non-YAML file may be returned as part of an error message. The attacker would have to know or guess the location of the target file. Sensitive files which could be leaked include files from other Applications' source repositories or any secrets which have been mounted as files on the repo-server. This vulnerability is patched in Argo CD versions 2.1.11, 2.2.6, and 2.3.0. The patches prevent path traversal and limit access to users who either A) have been granted Application `create` privileges or B) have been granted Application `get` privileges and are requesting details for a `repo_url` that has already been used for the given Application. There are currently no known workarounds.

    Published: 22 Mar 2022
    6.8
    Medium

    CVE-2022-24731

    Last Modified: 23 Apr 2025

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal vulnerability, allowing a malicious user with read/write access to leak sensitive files from Argo CD's repo-server. A malicious Argo CD user who has been granted `create` or `update` access to Applications can leak the contents of any text file on the repo-server. By crafting a malicious Helm chart and using it in an Application, the attacker can retrieve the sensitive file's contents either as part of the generated manifests or in an error message. The attacker would have to know or guess the location of the target file. Sensitive files which could be leaked include files from another Application's source repositories or any secrets which have been mounted as files on the repo-server. This vulnerability is patched in Argo CD versions 2.1.11, 2.2.6, and 2.3.0. The problem can be mitigated by avoiding storing secrets in git, avoiding mounting secrets as files on the repo-server, avoiding decrypting secrets into files on the repo-server, and carefully limiting who can `create` or `update` Applications.

    Published: 22 Mar 2022
    5.5
    Medium

    CVE-2022-25484

    Last Modified: 21 Nov 2024

    tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.

    Published: 22 Mar 2022
    7.1
    High

    CVE-2022-24774

    Last Modified: 23 Apr 2025

    CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit this vulnerability to create arbitrary directories or a denial of service by deleting arbitrary directories. The vulnerability is resolved in version 2.0.1. The vulnerability is not exploitable with the default configuration with the post and delete methods disabled. This can be configured by modifying the `appsettings.json` file, or alternatively, setting the environment variables `ALLOWEDMETHODS__POST` and `ALLOWEDMETHODS__DELETE` to `false`.

    Published: 22 Mar 2022
    3.4
    Low

    CVE-2022-21718

    Last Modified: 23 Apr 2025

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth API if the app has not configured a custom `select-bluetooth-device` event handler. This has been patched and Electron versions `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` contain the fix. Code from the GitHub Security Advisory can be added to the app to work around the issue.

    Published: 22 Mar 2022
    7.1
    High

    CVE-2022-3202

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2021-43650

    Last Modified: 21 Nov 2024

    WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.

    Published: 22 Mar 2022
    7.5
    High

    CVE-2022-1036

    Last Modified: 21 Nov 2024

    Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2021-45809

    Last Modified: 21 Nov 2024

    GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=<script>` parameter.

    Published: 22 Mar 2022
    7.2
    High

    CVE-2022-1034

    Last Modified: 21 Nov 2024

    There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

    Published: 22 Mar 2022
    8.1
    High

    CVE-2022-0759

    Last Modified: 21 Nov 2024

    A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

    Published: 22 Mar 2022
    9.8
    Critical

    CVE-2022-25517

    Last Modified: 21 Nov 2024

    MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.

    Published: 22 Mar 2022
    5.5
    Medium

    CVE-2022-1115

    Last Modified: 21 Nov 2024

    A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.

    Published: 22 Mar 2022
    7.5
    High

    CVE-2021-45810

    Last Modified: 21 Nov 2024

    GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect compatible server, the attack can redirect the entire host's traffic via their own server.

    Published: 22 Mar 2022
    7.5
    High

    CVE-2022-24764

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print(), pjmedia_sdp_media_print()`. Applications that do not use PJSUA2 and do not directly call `pjmedia_sdp_print()` or `pjmedia_sdp_media_print()` should not be affected. A patch is available on the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.

    Published: 22 Mar 2022
    3.3
    Low

    CVE-2022-0652

    Last Modified: 21 Nov 2024

    Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.

    Published: 21 Mar 2022
    8.8
    High

    CVE-2022-0386

    Last Modified: 21 Nov 2024

    A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.

    Published: 21 Mar 2022
    9.8
    Critical

    CVE-2022-26285

    Last Modified: 21 Nov 2024

    Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

    Published: 21 Mar 2022
    9.8
    Critical

    CVE-2022-26284

    Last Modified: 21 Nov 2024

    Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

    Published: 21 Mar 2022
    9.8
    Critical

    CVE-2022-26283

    Last Modified: 24 Feb 2025

    Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

    Published: 21 Mar 2022
    8.1
    High

    CVE-2022-27607

    Last Modified: 21 Nov 2024

    Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.

    Published: 21 Mar 2022
    9.8
    Critical

    CVE-2022-26174

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injected into the display fields.

    Published: 21 Mar 2022
    7.5
    High

    CVE-2022-27333

    Last Modified: 22 Apr 2025

    idcCMS v1.10 was discovered to contain an issue which allows attackers to arbitrarily delete the install.lock file, resulting in a reset of the CMS settings and data.

    Published: 21 Mar 2022
    5.4
    Medium

    CVE-2022-27090

    Last Modified: 21 Nov 2024

    Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.

    Published: 21 Mar 2022
    6.8
    Medium

    CVE-2021-38745

    Last Modified: 21 Nov 2024

    Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.

    Published: 21 Mar 2022