CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-0849

    Last Modified: 21 Nov 2024

    Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

    Published: 5 Mar 2022
    7.8
    High

    CVE-2022-25465

    Last Modified: 21 Nov 2024

    Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.

    Published: 5 Mar 2022
    7.8
    High

    CVE-2022-25044

    Last Modified: 21 Nov 2024

    Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.

    Published: 5 Mar 2022
    9.6
    Critical

    CVE-2022-25069

    Last Modified: 21 Nov 2024

    Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

    Published: 5 Mar 2022
    9.6
    Critical

    CVE-2022-26486

    Last Modified: 19 Aug 2026

    An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

    Published: 5 Mar 2022
    8.8
    High

    CVE-2022-26485

    Last Modified: 19 Aug 2026

    Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

    Published: 5 Mar 2022
    9.1
    Critical

    CVE-2022-25312

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Any23 2.7.

    Published: 4 Mar 2022
    9.8
    Critical

    CVE-2021-46384

    Last Modified: 21 Nov 2024

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2021-40846

    Last Modified: 21 Nov 2024

    An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

    Published: 4 Mar 2022
    8.8
    High

    CVE-2021-44827

    Last Modified: 21 Nov 2024

    There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.

    Published: 4 Mar 2022
    9.9
    Critical

    CVE-2021-32008

    Last Modified: 21 Nov 2024

    This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2021-27756

    Last Modified: 21 Nov 2024

    "TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."

    Published: 4 Mar 2022
    5.3
    Medium

    CVE-2021-46353

    Last Modified: 21 Nov 2024

    An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.

    Published: 4 Mar 2022
    6
    Medium

    CVE-2021-43590

    Last Modified: 21 Nov 2024

    Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

    Published: 4 Mar 2022
    7.2
    High

    CVE-2022-23915

    Last Modified: 21 Nov 2024

    The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.

    Published: 4 Mar 2022
    5.5
    Medium

    CVE-2022-25106

    Last Modified: 21 Nov 2024

    D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2021-27757

    Last Modified: 21 Nov 2024

    " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2022-0855

    Last Modified: 21 Nov 2024

    Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.

    Published: 4 Mar 2022
    4.9
    Medium

    CVE-2022-26484

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By manipulating the resource name in GET requests referring to files with absolute paths, it is possible to access arbitrary files stored on the filesystem, including application source code, configuration files, and critical system files.

    Published: 4 Mar 2022
    4.8
    Medium

    CVE-2022-26483

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter (which reflect the user input without sanitization).

    Published: 4 Mar 2022
    9.8
    Critical

    CVE-2022-26318

    Last Modified: 13 Nov 2025

    On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2022-23233

    Last Modified: 21 Nov 2024

    StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS) of the Local Distribution Router (LDR) service.

    Published: 4 Mar 2022
    4.9
    Medium

    CVE-2022-23232

    Last Modified: 21 Nov 2024

    StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user accounts to access S3 data to which they previously had access. StorageGRID 11.6.0 obtains the user account status from Active Directory or Azure and will block S3 access for disabled user accounts during the subsequent background synchronization. User accounts that are expired or locked for Active Directory or Azure, or user accounts that are disabled, expired, or locked in identity sources other than Active Directory or Azure must be manually removed from group memberships or have their S3 keys manually removed from Tenant Manager in all versions of StorageGRID (formerly StorageGRID Webscale).

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-24727

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-23915. Reason: This candidate is a reservation duplicate of CVE-2022-23915. Notes: All CVE users should reference CVE-2022-23915 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Mar 2022
    7.2
    High

    CVE-2022-21828

    Last Modified: 21 Nov 2024

    A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.

    Published: 4 Mar 2022
    7.8
    High

    CVE-2022-25623

    Last Modified: 21 Nov 2024

    The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations.

    Published: 4 Mar 2022
    7.8
    High

    CVE-2022-23729

    Last Modified: 21 Nov 2024

    When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

    Published: 4 Mar 2022
    5.5
    Medium

    CVE-2022-22946

    Last Modified: 21 Nov 2024

    In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates.

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2021-46382

    Last Modified: 21 Nov 2024

    Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2021-46381

    Last Modified: 21 Nov 2024

    Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2021-46380

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: Reason: This is a duplicate to CVE-2022-22511 Notes

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2021-46379

    Last Modified: 21 Nov 2024

    DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2021-46378

    Last Modified: 21 Nov 2024

    DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2020-18325

    Last Modified: 21 Nov 2024

    Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2020-18324

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

    Published: 4 Mar 2022
    8.8
    High

    CVE-2020-18326

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2020-18327

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-nodebrowser API. Fixed in v6.2

    Published: 4 Mar 2022
    5.4
    Medium

    CVE-2022-0832

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

    Published: 4 Mar 2022
    5.4
    Medium

    CVE-2022-0831

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.

    Published: 4 Mar 2022
    9.8
    Critical

    CVE-2022-26201

    Last Modified: 21 Nov 2024

    Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.

    Published: 4 Mar 2022
    9.8
    Critical

    CVE-2021-46394

    Last Modified: 21 Nov 2024

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check, which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data.

    Published: 4 Mar 2022
    9.8
    Critical

    CVE-2021-46393

    Last Modified: 21 Nov 2024

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security check,which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data.

    Published: 4 Mar 2022
    6.2
    Medium

    CVE-2021-43392

    Last Modified: 21 Nov 2024

    STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.

    Published: 4 Mar 2022
    6.2
    Medium

    CVE-2021-43393

    Last Modified: 21 Nov 2024

    STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.

    Published: 4 Mar 2022
    5
    Medium

    CVE-2021-44321

    Last Modified: 21 Nov 2024

    Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2022-0752

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2022-23328

    Last Modified: 21 Nov 2024

    A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS).

    Published: 4 Mar 2022
    7.5
    High

    CVE-2022-23327

    Last Modified: 21 Nov 2024

    A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS).

    Published: 4 Mar 2022
    9.8
    Critical

    CVE-2022-0848

    Last Modified: 21 Nov 2024

    OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2022-0838

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

    Published: 4 Mar 2022