CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2022-25601

    Last Modified: 20 Feb 2025

    Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2021-27414

    Last Modified: 16 Apr 2025

    An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visiting a malicious website posing as a login page for the Ellipse application and gather authentication credentials.

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2021-27416

    Last Modified: 16 Apr 2025

    An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code that would then be run by the web browser. This can result in the compromise of confidential information, or even the takeover of the user’s session.

    Published: 11 Mar 2022
    5
    Medium

    CVE-2021-32009

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

    Published: 11 Mar 2022
    6.7
    Medium

    CVE-2022-0921

    Last Modified: 21 Nov 2024

    Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

    Published: 11 Mar 2022
    8.1
    High

    CVE-2022-24433

    Last Modified: 21 Nov 2024

    The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary command execution.

    Published: 11 Mar 2022
    9.8
    Critical

    CVE-2021-44620

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

    Published: 11 Mar 2022
    9.8
    Critical

    CVE-2021-44618

    Last Modified: 21 Nov 2024

    A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.

    Published: 11 Mar 2022
    0
    Low

    CVE-2022-0931

    Last Modified: 8 Feb 2024

    Red Hat Product Security does not consider this to be a vulnerability. Upstream has not acknowledged this issue as a security flaw.

    Published: 11 Mar 2022
    9.1
    Critical

    CVE-2022-0860

    Last Modified: 21 Nov 2024

    Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

    Published: 11 Mar 2022
    5.3
    Medium

    CVE-2022-0870

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

    Published: 11 Mar 2022
    5.4
    Medium

    CVE-2022-0928

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.

    Published: 11 Mar 2022
    4.8
    Medium

    CVE-2022-0912

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.

    Published: 11 Mar 2022
    7.5
    High

    CVE-2022-0913

    Last Modified: 21 Nov 2024

    Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

    Published: 11 Mar 2022
    9.8
    Critical

    CVE-2022-23402

    Last Modified: 21 Nov 2024

    The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-23401

    Last Modified: 21 Nov 2024

    The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    8.8
    High

    CVE-2022-22729

    Last Modified: 21 Nov 2024

    CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    8.1
    High

    CVE-2022-22151

    Last Modified: 21 Nov 2024

    CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-22148

    Last Modified: 21 Nov 2024

    'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    8.1
    High

    CVE-2022-22145

    Last Modified: 21 Nov 2024

    CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-22141

    Last Modified: 21 Nov 2024

    'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    8.8
    High

    CVE-2022-21808

    Last Modified: 21 Nov 2024

    Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    9.8
    Critical

    CVE-2022-21194

    Last Modified: 21 Nov 2024

    The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    8.1
    High

    CVE-2022-21177

    Last Modified: 21 Nov 2024

    There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, andfrom R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

    Published: 11 Mar 2022
    6.1
    Medium

    CVE-2021-46708

    Last Modified: 21 Nov 2024

    The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.

    Published: 11 Mar 2022
    4.3
    Medium

    CVE-2018-25031

    Last Modified: 21 Nov 2024

    Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-27666

    Last Modified: 1 Sept 2026

    A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

    Published: 11 Mar 2022
    5.4
    Medium

    CVE-2022-26874

    Last Modified: 21 Nov 2024

    lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.

    Published: 11 Mar 2022
    7.8
    High

    CVE-2022-0995

    Last Modified: 26 Aug 2026

    An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

    Published: 11 Mar 2022
    5.4
    Medium

    CVE-2022-0822

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.

    Published: 11 Mar 2022
    4.3
    Medium

    CVE-2021-32472

    Last Modified: 21 Nov 2024

    Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.

    Published: 11 Mar 2022
    7.5
    High

    CVE-2021-32476

    Last Modified: 21 Nov 2024

    A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

    Published: 11 Mar 2022
    6.1
    Medium

    CVE-2021-32478

    Last Modified: 21 Nov 2024

    The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

    Published: 11 Mar 2022
    9.1
    Critical

    CVE-2022-0871

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

    Published: 11 Mar 2022
    —
    Unknown

    CVE-2022-0925

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 11 Mar 2022
    6.5
    Medium

    CVE-2022-0932

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2022-0907

    Last Modified: 21 Nov 2024

    Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2022-0909

    Last Modified: 21 Nov 2024

    Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2022-0924

    Last Modified: 21 Nov 2024

    Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.

    Published: 11 Mar 2022
    6.8
    Medium

    CVE-2021-33150

    Last Modified: 5 May 2025

    Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 11 Mar 2022
    5.5
    Medium

    CVE-2022-26878

    Last Modified: 5 May 2025

    drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated but not freed).

    Published: 11 Mar 2022
    7.7
    High

    CVE-2022-0908

    Last Modified: 21 Nov 2024

    Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.

    Published: 11 Mar 2022
    7.6
    High

    CVE-2022-21819

    Last Modified: 21 Nov 2024

    NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through the PCI bus. Such an attack could result in denial of service, code execution, escalation of privileges, and impact to data integrity and confidentiality. The scope impact may extend to other components.

    Published: 11 Mar 2022
    8.5
    High

    CVE-2022-24754

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stack-buffer overflow vulnerability which only impacts PJSIP users who accept hashed digest credentials (credentials with data_type `PJSIP_CRED_DATA_DIGEST`). This issue has been patched in the master branch of the PJSIP repository and will be included with the next release. Users unable to upgrade need to check that the hashed digest data length must be equal to `PJSIP_MD5STRLEN` before passing to PJSIP.

    Published: 11 Mar 2022
    6.5
    Medium

    CVE-2022-0821

    Last Modified: 21 Nov 2024

    Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

    Published: 10 Mar 2022
    7.5
    High

    CVE-2022-25512

    Last Modified: 21 Nov 2024

    FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.

    Published: 10 Mar 2022
    8.8
    High

    CVE-2022-25510

    Last Modified: 21 Nov 2024

    FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.

    Published: 10 Mar 2022
    6.5
    Medium

    CVE-2022-25511

    Last Modified: 21 Nov 2024

    An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.

    Published: 10 Mar 2022
    7.5
    High

    CVE-2022-25508

    Last Modified: 21 Nov 2024

    An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.

    Published: 10 Mar 2022
    6.5
    Medium

    CVE-2022-25506

    Last Modified: 21 Nov 2024

    FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.

    Published: 10 Mar 2022