CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-1050

    Last Modified: 21 Nov 2024

    A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.

    Published: 21 Mar 2022
    9.8
    Critical

    CVE-2022-26184

    Last Modified: 21 Nov 2024

    Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

    Published: 21 Mar 2022
    5.5
    Medium

    CVE-2022-3597

    Last Modified: 7 May 2025

    LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.

    Published: 21 Mar 2022
    5.5
    Medium

    CVE-2022-3627

    Last Modified: 7 May 2025

    LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.

    Published: 21 Mar 2022
    8.8
    High

    CVE-2021-40662

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.

    Published: 21 Mar 2022
    5.5
    Medium

    CVE-2022-48619

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the situation in which an event code falls outside of a bitmap.

    Published: 21 Mar 2022
    7.1
    High

    CVE-2022-1353

    Last Modified: 21 Nov 2024

    A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.

    Published: 21 Mar 2022
    9.8
    Critical

    CVE-2022-26148

    Last Modified: 21 Nov 2024

    An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

    Published: 21 Mar 2022
    8.8
    High

    CVE-2022-26183

    Last Modified: 21 Nov 2024

    PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

    Published: 21 Mar 2022
    7.8
    High

    CVE-2022-2964

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.

    Published: 21 Mar 2022
    9.8
    Critical

    CVE-2021-39384

    Last Modified: 21 Nov 2024

    DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.

    Published: 20 Mar 2022
    7.2
    High

    CVE-2021-42194

    Last Modified: 21 Nov 2024

    The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.

    Published: 20 Mar 2022
    9.8
    Critical

    CVE-2021-39383

    Last Modified: 21 Nov 2024

    DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.

    Published: 20 Mar 2022
    7.8
    High

    CVE-2020-26008

    Last Modified: 21 Nov 2024

    The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 20 Mar 2022
    7.8
    High

    CVE-2020-26007

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 20 Mar 2022
    7.5
    High

    CVE-2022-25462

    Last Modified: 21 Nov 2024

    Yafu v2.0 contains a segmentation fault via the component /factor/avx-ecm/vecarith52.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

    Published: 20 Mar 2022
    5.4
    Medium

    CVE-2022-26555

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box.

    Published: 20 Mar 2022
    6.1
    Medium

    CVE-2022-26246

    Last Modified: 21 Nov 2024

    TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate.

    Published: 20 Mar 2022
    5.9
    Medium

    CVE-2022-26247

    Last Modified: 21 Nov 2024

    TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify the administrator account and password.

    Published: 20 Mar 2022
    4.8
    Medium

    CVE-2022-25464

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 20 Mar 2022
    7.5
    High

    CVE-2021-44345

    Last Modified: 21 Nov 2024

    Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.

    Published: 20 Mar 2022
    8.8
    High

    CVE-2022-24125

    Last Modified: 21 Nov 2024

    The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToPlayers request. For example, ability to send a push message to hundreds of thousands of machines is only restricted on the client side, and can thus be bypassed with a modified client.

    Published: 20 Mar 2022
    7.5
    High

    CVE-2022-25481

    Last Modified: 21 Nov 2024

    ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

    Published: 20 Mar 2022
    9.8
    Critical

    CVE-2022-24126

    Last Modified: 21 Nov 2024

    A buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allows remote attackers to execute arbitrary code via matchmaking servers, a different vulnerability than CVE-2021-34170.

    Published: 19 Mar 2022
    7.1
    High

    CVE-2022-0991

    Last Modified: 21 Nov 2024

    Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.

    Published: 19 Mar 2022
    8.8
    High

    CVE-2022-27226

    Last Modified: 21 Nov 2024

    A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.

    Published: 19 Mar 2022
    7.5
    High

    CVE-2022-26267

    Last Modified: 21 Nov 2024

    Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-26265

    Last Modified: 21 Nov 2024

    Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

    Published: 18 Mar 2022
    8.8
    High

    CVE-2022-26266

    Last Modified: 21 Nov 2024

    Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.

    Published: 18 Mar 2022
    7.8
    High

    CVE-2022-25581

    Last Modified: 21 Nov 2024

    Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25578

    Last Modified: 21 Nov 2024

    taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25390

    Last Modified: 21 Nov 2024

    DCN Firewall DCME-520 was discovered to contain a remote command execution (RCE) vulnerability via the host parameter in the file /system/tool/ping.php.

    Published: 18 Mar 2022
    7.5
    High

    CVE-2022-25389

    Last Modified: 21 Nov 2024

    DCN Firewall DCME-520 was discovered to contain an arbitrary file download vulnerability via the path parameter in the file /audit/log/log_management.php.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25460

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25461

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25459

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25458

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25457

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25455

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25456

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25454

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25452

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25453

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25451

    Last Modified: 21 Nov 2024

    Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25449

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25450

    Last Modified: 21 Nov 2024

    Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25448

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25447

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25446

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.

    Published: 18 Mar 2022
    9.8
    Critical

    CVE-2022-25445

    Last Modified: 21 Nov 2024

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

    Published: 18 Mar 2022