CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2022-0930

    Last Modified: 21 Nov 2024

    File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

    Published: 12 Mar 2022
    6.1
    Medium

    CVE-2022-0929

    Last Modified: 21 Nov 2024

    XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.

    Published: 12 Mar 2022
    4.8
    Medium

    CVE-2022-0926

    Last Modified: 21 Nov 2024

    File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

    Published: 12 Mar 2022
    5.4
    Medium

    CVE-2022-0880

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

    Published: 12 Mar 2022
    7.8
    High

    CVE-2022-2977

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate privileges on the system.

    Published: 12 Mar 2022
    6.1
    Medium

    CVE-2022-26533

    Last Modified: 13 Feb 2026

    Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.

    Published: 12 Mar 2022
    5.3
    Medium

    CVE-2022-26276

    Last Modified: 21 Nov 2024

    An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.

    Published: 12 Mar 2022
    7.8
    High

    CVE-2022-26967

    Last Modified: 21 Nov 2024

    GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box.

    Published: 12 Mar 2022
    10
    Critical

    CVE-2022-24760

    Last Modified: 22 Apr 2025

    Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the Prototype Pollution vulnerable code in the file `DatabaseController.js`, so it is likely to affect Postgres and any other database backend as well. This vulnerability has been confirmed on Linux (Ubuntu) and Windows. Users are advised to upgrade as soon as possible. The only known workaround is to manually patch your installation with code referenced at the source GHSA-p6h4-93qp-jhcm.

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2021-41849

    Last Modified: 21 Nov 2024

    An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and device International Mobile Equipment Identity (IMEI). This PII is transmitted to log.skyroam.com.cn using HTTP, independent of whether the user uses the Simo software.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2021-41848

    Last Modified: 21 Nov 2024

    An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and arbitrary ARM binary, where both will be executed as the root user with an SELinux domain named osi. To exploit this vulnerability, a local third-party app needs to have write access to external storage to write the spoofed update at the expected path. The vulnerable system binary (i.e., /system/bin/osi_bin) does not perform any authentication of the update file beyond ensuring that it is encrypted with an AES key (that is hard-coded in the vulnerable system binary). Processes executing with the osi SELinux domain can programmatically perform the following actions: install apps, grant runtime permissions to apps (including permissions with protection levels of dangerous and development), access extensive Personally Identifiable Information (PII) using the programmatically grant permissions, uninstall apps, set the default launcher app to a malicious launcher app that spoofs other apps, set a network proxy to intercept network traffic, unload kernel modules, set the default keyboard to a keyboard that has keylogging functionality, examine notification contents, send text messages, and more. The spoofed update can optionally contain an arbitrary ARM binary that will be locally stored in internal storage and executed at system startup to achieve persistent code execution as the root user with the osi SELinux domain. This ARM binary will continue to execute at startup even if the app that provided the spoofed update is uninstalled.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2021-41850

    Last Modified: 21 Nov 2024

    An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property values can be obtained via getprop by all third-party applications co-located on the device, even those with no permissions granted, exposing the IMEI values to processes without enforcing any access control.

    Published: 11 Mar 2022
    7.5
    High

    CVE-2021-42577

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.

    Published: 11 Mar 2022
    6.5
    Medium

    CVE-2021-42262

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-24421

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-24420

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-24419

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-24416

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-24415

    Last Modified: 21 Nov 2024

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution during SMM.

    Published: 11 Mar 2022
    4.3
    Medium

    CVE-2022-25839

    Last Modified: 21 Nov 2024

    The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\\\\\localhost and http://localhost are the same URL. However, the hostname is not parsed as localhost, and the backslash is reflected as it is.

    Published: 11 Mar 2022
    6.1
    Medium

    CVE-2021-44667

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.

    Published: 11 Mar 2022
    6.5
    Medium

    CVE-2022-23625

    Last Modified: 23 Apr 2025

    Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. These malformed resource identifiers can be generated and sent between Wire users. The root cause lies in [wireapp/wire-ios-transport](https://github.com/wireapp/wire-ios-transport), where code responsible for removing sensible tokens before logging may fail and lead to a crash (Swift exception) of the application. This causes undesirable behavior, however the (greater) Wire system is still functional. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Published: 11 Mar 2022
    7.5
    High

    CVE-2021-23246

    Last Modified: 21 Nov 2024

    In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosure.

    Published: 11 Mar 2022
    7.5
    High

    CVE-2022-25216

    Last Modified: 21 Nov 2024

    An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2022-24090

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-24096

    Last Modified: 23 Apr 2025

    Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-23187

    Last Modified: 23 Apr 2025

    Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Illustrator.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-24094

    Last Modified: 23 Apr 2025

    Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-24097

    Last Modified: 23 Apr 2025

    Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-24095

    Last Modified: 23 Apr 2025

    Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2022
    9.8
    Critical

    CVE-2022-25621

    Last Modified: 21 Nov 2024

    UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE WA 2611-AP Ver8.2.11 and prior, UNIVERGE WA 2611E-AP Ver8.2.11 and prior, UNIVERGE WA WA2612-AP Ver8.2.11 and prior allows a remote attacker to execute arbitrary OS commands.

    Published: 11 Mar 2022
    7.2
    High

    CVE-2021-32474

    Last Modified: 21 Nov 2024

    An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

    Published: 11 Mar 2022
    5.3
    Medium

    CVE-2021-32473

    Last Modified: 21 Nov 2024

    It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected

    Published: 11 Mar 2022
    5.4
    Medium

    CVE-2021-32475

    Last Modified: 21 Nov 2024

    ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

    Published: 11 Mar 2022
    4.3
    Medium

    CVE-2021-32477

    Last Modified: 21 Nov 2024

    The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2021-33658

    Last Modified: 2 Apr 2025

    atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23933

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23932

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23928

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23929

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23927

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23926

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23934

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23931

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23930

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23925

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    8.2
    High

    CVE-2022-23924

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products which may allow Escalation of Privilege, Arbitrary Code Execution, Unauthorized Code Execution, Denial of Service, and Information Disclosure.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-23731

    Last Modified: 21 Nov 2024

    V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.

    Published: 11 Mar 2022
    9.8
    Critical

    CVE-2022-23730

    Last Modified: 21 Nov 2024

    The public API error causes for the attacker to be able to bypass API access control.

    Published: 11 Mar 2022
    5.4
    Medium

    CVE-2022-25600

    Last Modified: 7 May 2025

    Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).

    Published: 11 Mar 2022