CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-40047

    Last Modified: 21 Nov 2024

    There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40048

    Last Modified: 21 Nov 2024

    There is an incorrect buffer size calculation vulnerability in the video framework. Successful exploitation of this vulnerability will affect availability.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40049

    Last Modified: 21 Nov 2024

    There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2021-40050

    Last Modified: 21 Nov 2024

    There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40051

    Last Modified: 21 Nov 2024

    There is an unauthorized access vulnerability in system components. Successful exploitation of this vulnerability will affect confidentiality.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40052

    Last Modified: 21 Nov 2024

    There is an incorrect buffer size calculation vulnerability in the video framework.Successful exploitation of this vulnerability may affect availability.

    Published: 7 Mar 2022
    9.1
    Critical

    CVE-2021-40053

    Last Modified: 21 Nov 2024

    There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40054

    Last Modified: 21 Nov 2024

    There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may affect integrity.

    Published: 7 Mar 2022
    5.9
    Medium

    CVE-2021-40055

    Last Modified: 21 Nov 2024

    There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40056

    Last Modified: 21 Nov 2024

    There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerability may affect availability.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40057

    Last Modified: 21 Nov 2024

    There is a heap-based and stack-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40058

    Last Modified: 21 Nov 2024

    There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2021-40059

    Last Modified: 21 Nov 2024

    There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40060

    Last Modified: 21 Nov 2024

    There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability may affect availability.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40061

    Last Modified: 21 Nov 2024

    There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vulnerability may affect integrity.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40062

    Last Modified: 21 Nov 2024

    There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerability may affect availability.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40063

    Last Modified: 21 Nov 2024

    There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 7 Mar 2022
    7.5
    High

    CVE-2021-40064

    Last Modified: 21 Nov 2024

    There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stability.

    Published: 7 Mar 2022
    —
    Unknown

    CVE-2021-42186

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2022-24193

    Last Modified: 21 Nov 2024

    CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-0754

    Last Modified: 21 Nov 2024

    SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2021-4199

    Last Modified: 21 Nov 2024

    Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender Internet Security versions prior to 26.0.10.45. Bitdefender Antivirus Plus versions prior to 26.0.10.45. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.3.146.

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2021-4198

    Last Modified: 21 Nov 2024

    A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total Security versions prior to 26.0.3.29. Bitdefender Internet Security versions prior to 26.0.3.29. Bitdefender Antivirus Plus versions prior to 26.0.3.29. Bitdefender Endpoint Security Tools versions prior to 7.2.2.92. Bitdefender VPN Standalone versions prior to 25.5.0.48.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-1011

    Last Modified: 26 Aug 2026

    A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

    Published: 7 Mar 2022
    5.5
    Medium

    CVE-2022-0854

    Last Modified: 21 Nov 2024

    A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-25325

    Last Modified: 21 Nov 2024

    Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25230.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-25234

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-21124.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-25230

    Last Modified: 21 Nov 2024

    Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25325.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-21219

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.

    Published: 7 Mar 2022
    3.7
    Low

    CVE-2022-21170

    Last Modified: 21 Nov 2024

    Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and earlier, and D-SPA (Ver.3 / Ver.4) using i-FILTER allows a remote unauthenticated attacker to conduct a man-in-the-middle attack and eavesdrop on an encrypted communication.

    Published: 7 Mar 2022
    5.4
    Medium

    CVE-2022-21158

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on the PC of the user using marktext.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-21132

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.

    Published: 7 Mar 2022
    7.8
    High

    CVE-2022-21124

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25234.

    Published: 7 Mar 2022
    4.8
    Medium

    CVE-2022-0535

    Last Modified: 21 Nov 2024

    The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2022-0533

    Last Modified: 21 Nov 2024

    The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

    Published: 7 Mar 2022
    4.8
    Medium

    CVE-2022-0448

    Last Modified: 21 Nov 2024

    The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

    Published: 7 Mar 2022
    6.5
    Medium

    CVE-2022-0445

    Last Modified: 21 Nov 2024

    The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack

    Published: 7 Mar 2022
    4.3
    Medium

    CVE-2022-0442

    Last Modified: 21 Nov 2024

    The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2022-0441

    Last Modified: 21 Nov 2024

    The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

    Published: 7 Mar 2022
    7.2
    High

    CVE-2022-0440

    Last Modified: 21 Nov 2024

    The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)

    Published: 7 Mar 2022
    8.8
    High

    CVE-2022-0439

    Last Modified: 21 Nov 2024

    The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2022-0434

    Last Modified: 21 Nov 2024

    The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2022-0429

    Last Modified: 21 Nov 2024

    The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

    Published: 7 Mar 2022
    5.4
    Medium

    CVE-2022-0426

    Last Modified: 21 Nov 2024

    The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

    Published: 7 Mar 2022
    6.1
    Medium

    CVE-2022-0422

    Last Modified: 21 Nov 2024

    The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

    Published: 7 Mar 2022
    7.2
    High

    CVE-2022-0420

    Last Modified: 21 Nov 2024

    The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

    Published: 7 Mar 2022
    8.8
    High

    CVE-2022-0410

    Last Modified: 6 Mar 2026

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection

    Published: 7 Mar 2022
    4.8
    Medium

    CVE-2022-0389

    Last Modified: 21 Nov 2024

    The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 7 Mar 2022
    4.3
    Medium

    CVE-2022-0384

    Last Modified: 21 Nov 2024

    The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

    Published: 7 Mar 2022
    9.8
    Critical

    CVE-2022-0349

    Last Modified: 21 Nov 2024

    The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

    Published: 7 Mar 2022