CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-26386

    Last Modified: 15 Apr 2025

    Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users. This behavior was reverted to the original, user-specific directory. <br>*This bug only affects Firefox for macOS and Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.7 and Thunderbird < 91.7.

    Published: 8 Mar 2022
    7.2
    High

    CVE-2022-24282

    Last Modified: 21 Apr 2025

    A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected system allows to upload JSON objects that are deserialized to Java objects. Due to insecure deserialization of user-supplied content by the affected software, a privileged attacker could exploit this vulnerability by sending a maliciously crafted serialized Java object. This could allow the attacker to execute arbitrary code on the device with root privileges.

    Published: 8 Mar 2022
    8.8
    High

    CVE-2022-26381

    Last Modified: 16 Apr 2025

    An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

    Published: 8 Mar 2022
    9.6
    Critical

    CVE-2022-26384

    Last Modified: 16 Apr 2025

    If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

    Published: 8 Mar 2022
    7.5
    High

    CVE-2022-26387

    Last Modified: 15 Apr 2025

    When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

    Published: 8 Mar 2022
    6.1
    Medium

    CVE-2021-36809

    Last Modified: 21 Nov 2024

    A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-24737

    Last Modified: 22 Apr 2025

    HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTTPie didn‘t distinguish between cookies and hosts they belonged. This behavior resulted in the exposure of some cookies when there are redirects originating from the actual host to a third party website. Users are advised to upgrade. There are no known workarounds.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-26661

    Last Modified: 21 Nov 2024

    An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2022-26662

    Last Modified: 21 Nov 2024

    An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-34338

    Last Modified: 21 Nov 2024

    Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-34339

    Last Modified: 21 Nov 2024

    Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-34340

    Last Modified: 21 Nov 2024

    Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-34341

    Last Modified: 21 Nov 2024

    Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-34342

    Last Modified: 21 Nov 2024

    Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak.

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2021-4045

    Last Modified: 21 Nov 2024

    TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.

    Published: 7 Mar 2022
    8.4
    High

    CVE-2022-25219

    Last Modified: 21 Nov 2024

    A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that allow a user to spawn a telnet service on the router, and to ensure that the telnet service persists upon reboot. By means of a crafted exchange of UDP packets, an unauthenticated attacker on the local network can leverage this null byte interaction error in such a way as to make those ephemeral passwords predictable (with 1-in-94 odds). Since the attacker must manipulate data processed by the OpenSSL function RSA_public_decrypt(), successful exploitation of this vulnerability depends on the use of an unpadded RSA cipher (CVE-2022-25218).

    Published: 7 Mar 2022
    8.8
    High

    CVE-2022-24644

    Last Modified: 21 Nov 2024

    ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit this vulnerability, a user must trigger an update of an affected installation of KeyMouse.

    Published: 7 Mar 2022
    6.8
    Medium

    CVE-2022-25213

    Last Modified: 21 Nov 2024

    Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.

    Published: 7 Mar 2022
    5.3
    Medium

    CVE-2022-25215

    Last Modified: 21 Nov 2024

    Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself.

    Published: 7 Mar 2022
    8.1
    High

    CVE-2022-25218

    Last Modified: 21 Nov 2024

    The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area network to achieve a significant degree of control over the "plaintext" to which an arbitrary blob of ciphertext will be decrypted by OpenSSL's RSA_public_decrypt() function. This weakness allows the attacker to manipulate the various iterations of the telnetd startup state machine and eventually obtain a root shell on the device, by means of an exchange of crafted UDP packets. In all versions but K2 22.5.9.163 and K3C 32.1.15.93 a successful attack also requires the exploitation of a null-byte interaction error (CVE-2022-25219).

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-25217

    Last Modified: 21 Nov 2024

    Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmware, and version 32.1.15.93 of the K3C firmware (possibly amongst many other releases) included both the private and public RSA keys. The remaining versions cited here redacted the private key, but left the public key unchanged. An attacker in possession of the leaked private key may, through a scripted exchange of UDP packets, instruct telnetd_startup to spawn an unauthenticated telnet shell as root, by means of which they can then obtain complete control of the device. A consequence of the limited availablility of firmware images for testing is that models and versions not listed here may share this vulnerability.

    Published: 7 Mar 2022
    7.4
    High

    CVE-2022-25214

    Last Modified: 21 Nov 2024

    Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Improper access control on the wirelesssetup.asp interface allows an unauthenticated remote attacker to obtain the WPA passphrases for the 2.4GHz and 5.0GHz wireless networks. This is particularly dangerous given that the K2G setup wizard presents the user with the option of using the same password for the 2.4Ghz network and the administrative interface, by clicking a checkbox. When Remote Managment is enabled, these endpoints are exposed to the WAN.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-25243

    Last Modified: 21 Nov 2024

    "Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-25244

    Last Modified: 21 Nov 2024

    Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.

    Published: 7 Mar 2022
    8.1
    High

    CVE-2022-24738

    Last Modified: 23 Apr 2025

    Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed funds from user addresses. To do this an attacker must create a new chain which does not enforce signature verification and connects it to the target evmos instance. The attacker can use this joined chain to transfer unclaimed funds. Users are advised to upgrade. There are no known workarounds for this issue.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2020-36517

    Last Modified: 21 Nov 2024

    An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2021-41657

    Last Modified: 21 Nov 2024

    SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.

    Published: 7 Mar 2022
    8.8
    High

    CVE-2021-43970

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-43969

    Last Modified: 21 Nov 2024

    The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.

    Published: 7 Mar 2022
    8.8
    High

    CVE-2022-22834

    Last Modified: 21 Nov 2024

    An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XSLT Injection vulnerability. Attackers could exploit this issue to achieve remote code execution.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-22835

    Last Modified: 21 Nov 2024

    An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2022-26311

    Last Modified: 21 Nov 2024

    Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor. Secrets are not redacted in logs collected from Kubernetes environments.

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2022-24177

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the component cgi-bin/ej.cgi of Ex libris ALEPH 500 v18.1 and v20 allows attackers to execute arbitrary web scripts or HTML.

    Published: 7 Mar 2022
    8.8
    High

    CVE-2022-23940

    Last Modified: 21 Nov 2024

    SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-25294

    Last Modified: 21 Nov 2024

    Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows user to run arbitrary code with SYSTEM privileges. All versions prior to 7.12.1 are affected. Agents for MacOS and Linux and Cloud are unaffected. Proofpoint has released fixed software version 7.12.1. The fixed software versions are available through the customer support portal.

    Published: 7 Mar 2022
    7
    High

    CVE-2022-26488

    Last Modified: 21 Nov 2024

    In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2.

    Published: 7 Mar 2022
    8.6
    High

    CVE-2022-22351

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396

    Published: 7 Mar 2022
    5.5
    Medium

    CVE-2021-38989

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951.

    Published: 7 Mar 2022
    5.5
    Medium

    CVE-2021-38988

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950.

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2020-14115

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

    Published: 7 Mar 2022
    9.3
    Critical

    CVE-2022-26131

    Last Modified: 16 Apr 2025

    Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2022-25922

    Last Modified: 16 Apr 2025

    Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked by replaying J2497 messages. There is no authentication or authorization for these functions.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2020-14111

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-32005

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This issue affects: Secomea SiteManager Version 9.6.621421014 and all prior versions.

    Published: 7 Mar 2022
    9.1
    Critical

    CVE-2022-23383

    Last Modified: 21 Nov 2024

    YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

    Published: 7 Mar 2022
    5
    Medium

    CVE-2021-32006

    Last Modified: 21 Nov 2024

    This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.

    Published: 7 Mar 2022
    5.5
    Medium

    CVE-2021-44215

    Last Modified: 21 Nov 2024

    Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.

    Published: 7 Mar 2022
    5.5
    Medium

    CVE-2021-44216

    Last Modified: 21 Nov 2024

    Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.

    Published: 7 Mar 2022
    5.3
    Medium

    CVE-2020-14112

    Last Modified: 21 Nov 2024

    Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can exploit this vulnerability to download part of the files in Xiaomi Router AX6000.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2022-0725

    Last Modified: 21 Nov 2024

    A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

    Published: 7 Mar 2022