CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-22007

    Last Modified: 8 Jul 2025

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 9 Mar 2022
    7.8
    High

    CVE-2022-22006

    Last Modified: 8 Jul 2025

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 9 Mar 2022
    8.8
    High

    CVE-2022-21990

    Last Modified: 8 Jul 2025

    Remote Desktop Client Remote Code Execution Vulnerability

    Published: 9 Mar 2022
    3.3
    Low

    CVE-2022-21977

    Last Modified: 8 Jul 2025

    Media Foundation Information Disclosure Vulnerability

    Published: 9 Mar 2022
    4.7
    Medium

    CVE-2022-21975

    Last Modified: 8 Jul 2025

    Windows Hyper-V Denial of Service Vulnerability

    Published: 9 Mar 2022
    5.5
    Medium

    CVE-2022-21973

    Last Modified: 8 Jul 2025

    Windows Media Center Update Denial of Service Vulnerability

    Published: 9 Mar 2022
    7
    High

    CVE-2022-21967

    Last Modified: 8 Jul 2025

    Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability

    Published: 9 Mar 2022
    6.6
    Medium

    CVE-2022-20060

    Last Modified: 21 Nov 2024

    In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06137462.

    Published: 9 Mar 2022
    6.6
    Medium

    CVE-2022-20059

    Last Modified: 21 Nov 2024

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160781.

    Published: 9 Mar 2022
    6.6
    Medium

    CVE-2022-20058

    Last Modified: 21 Nov 2024

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160485.

    Published: 9 Mar 2022
    6.5
    Medium

    CVE-2022-20057

    Last Modified: 21 Nov 2024

    In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; Issue ID: ALPS06271186.

    Published: 9 Mar 2022
    6.6
    Medium

    CVE-2022-20056

    Last Modified: 21 Nov 2024

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160820.

    Published: 9 Mar 2022
    6.8
    Medium

    CVE-2022-20055

    Last Modified: 21 Nov 2024

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160830.

    Published: 9 Mar 2022
    7.8
    High

    CVE-2022-20054

    Last Modified: 21 Nov 2024

    In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219083; Issue ID: ALPS06219083.

    Published: 9 Mar 2022
    5.5
    Medium

    CVE-2022-20051

    Last Modified: 21 Nov 2024

    In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219127; Issue ID: ALPS06219127.

    Published: 9 Mar 2022
    6.7
    Medium

    CVE-2022-20050

    Last Modified: 21 Nov 2024

    In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06335038; Issue ID: ALPS06335038.

    Published: 9 Mar 2022
    6.7
    Medium

    CVE-2022-20049

    Last Modified: 21 Nov 2024

    In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05954679; Issue ID: ALPS05954679.

    Published: 9 Mar 2022
    7.8
    High

    CVE-2022-20053

    Last Modified: 21 Nov 2024

    In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219097; Issue ID: ALPS06219097.

    Published: 9 Mar 2022
    7.8
    High

    CVE-2022-20048

    Last Modified: 21 Nov 2024

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917502; Issue ID: ALPS05917502.

    Published: 9 Mar 2022
    7.8
    High

    CVE-2022-20047

    Last Modified: 21 Nov 2024

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917489; Issue ID: ALPS05917489.

    Published: 9 Mar 2022
    5.4
    Medium

    CVE-2021-33852

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root page after duplicating any of the existing posts.

    Published: 9 Mar 2022
    5.4
    Medium

    CVE-2021-33851

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

    Published: 9 Mar 2022
    9.8
    Critical

    CVE-2021-42854

    Last Modified: 21 Nov 2024

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.

    Published: 9 Mar 2022
    4.7
    Medium

    CVE-2021-42856

    Last Modified: 21 Nov 2024

    It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to craft its own malicious payload to trigger a XSS vulnerability.

    Published: 9 Mar 2022
    9.4
    Critical

    CVE-2021-42787

    Last Modified: 21 Nov 2024

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.

    Published: 9 Mar 2022
    5.3
    Medium

    CVE-2021-42857

    Last Modified: 21 Nov 2024

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not have any validation of the user's input that allows a malicious payload to be injected.

    Published: 9 Mar 2022
    7.8
    High

    CVE-2021-42855

    Last Modified: 21 Nov 2024

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by the "/api/appInternals/1.0/agent/configuration" API to map the corresponding ID to a command to be executed.

    Published: 9 Mar 2022
    9.8
    Critical

    CVE-2021-42786

    Last Modified: 21 Nov 2024

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validation of the user's input that allowed a malicious payload to be injected.

    Published: 9 Mar 2022
    9.1
    Critical

    CVE-2021-42853

    Last Modified: 21 Nov 2024

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.

    Published: 9 Mar 2022
    6.1
    Medium

    CVE-2022-24397

    Last Modified: 21 Nov 2024

    SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser.

    Published: 9 Mar 2022
    8.1
    High

    CVE-2021-36777

    Last Modified: 21 Nov 2024

    A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.

    Published: 9 Mar 2022
    5.3
    Medium

    CVE-2021-35251

    Last Modified: 21 Nov 2024

    Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.

    Published: 9 Mar 2022
    8.1
    High

    CVE-2022-25090

    Last Modified: 21 Nov 2024

    Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.

    Published: 9 Mar 2022
    5.5
    Medium

    CVE-2022-24432

    Last Modified: 16 Apr 2025

    Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into specific fields. The XSS payload will be executed when a legitimate user attempts to upload, copy, download, or delete an existing configuration (Administrative Services).

    Published: 9 Mar 2022
    8
    High

    CVE-2022-24915

    Last Modified: 16 Apr 2025

    The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitimate user accesses the web section where the information is displayed. Injection can be done on specific parameters. The injected code is executed when a legitimate user attempts to upload, copy, download, or delete an existing configuration (Administrative Services).

    Published: 9 Mar 2022
    8.8
    High

    CVE-2022-22985

    Last Modified: 16 Apr 2025

    The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitimate user accesses the specific web section where the information is displayed. Injection can be done on specific parameters. The injected code is executed when a legitimate user attempts to review history.

    Published: 9 Mar 2022
    6.3
    Medium

    CVE-2022-21146

    Last Modified: 16 Apr 2025

    Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into a specific parameter. The XSS payload will be executed when a legitimate user attempts to review history.

    Published: 9 Mar 2022
    9.8
    Critical

    CVE-2022-26143

    Last Modified: 3 Nov 2025

    The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

    Published: 9 Mar 2022
    4.3
    Medium

    CVE-2022-0904

    Last Modified: 6 Dec 2024

    A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.

    Published: 9 Mar 2022
    5.3
    Medium

    CVE-2022-0903

    Last Modified: 6 Dec 2024

    A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.

    Published: 9 Mar 2022
    —
    Unknown

    CVE-2021-32505

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 9 Mar 2022
    —
    Unknown

    CVE-2021-32502

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 9 Mar 2022
    —
    Unknown

    CVE-2021-32501

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 9 Mar 2022
    5.8
    Medium

    CVE-2022-0507

    Last Modified: 21 Nov 2024

    Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.

    Published: 9 Mar 2022
    4.4
    Medium

    CVE-2022-0168

    Last Modified: 21 Nov 2024

    A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the system.

    Published: 9 Mar 2022
    5.3
    Medium

    CVE-2022-0813

    Last Modified: 21 Nov 2024

    PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

    Published: 9 Mar 2022
    4.4
    Medium

    CVE-2022-26355

    Last Modified: 21 Nov 2024

    Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.

    Published: 9 Mar 2022
    6.8
    Medium

    CVE-2022-22795

    Last Modified: 21 Nov 2024

    Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the product is running with root on Linux systems and nt/authority on windows systems, which allows him to access and extract any file on the systems, such as passwd, shadow, hosts and so on. By gaining access to these files, attackers can steal sensitive information from the victims machine.

    Published: 9 Mar 2022
    9.8
    Critical

    CVE-2022-24609

    Last Modified: 21 Nov 2024

    Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

    Published: 9 Mar 2022
    6.1
    Medium

    CVE-2022-24608

    Last Modified: 21 Nov 2024

    Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.

    Published: 9 Mar 2022