CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-26123

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26039

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-21224

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-25968

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26053

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-25920

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-25997

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26031

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26339

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26347

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26055

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26418

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26027

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-25889

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-25957

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26416

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26058

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    —
    Unknown

    CVE-2022-26087

    Last Modified: 7 Nov 2023

    This candidate was in a CNA pool that was not assigned to any issues during 2022.

    Published: 4 Mar 2022
    6.1
    Medium

    CVE-2022-23397

    Last Modified: 21 Nov 2024

    The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."

    Published: 4 Mar 2022
    5.5
    Medium

    CVE-2022-26336

    Last Modified: 21 Nov 2024

    A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.

    Published: 4 Mar 2022
    7.5
    High

    CVE-2022-0853

    Last Modified: 21 Nov 2024

    A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

    Published: 4 Mar 2022
    6.7
    Medium

    CVE-2022-22943

    Last Modified: 21 Nov 2024

    VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.

    Published: 3 Mar 2022
    4.8
    Medium

    CVE-2022-25220

    Last Modified: 21 Nov 2024

    PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding.

    Published: 3 Mar 2022
    6.5
    Medium

    CVE-2022-23052

    Last Modified: 21 Nov 2024

    PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application.

    Published: 3 Mar 2022
    5.4
    Medium

    CVE-2022-23051

    Last Modified: 21 Nov 2024

    PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter.

    Published: 3 Mar 2022
    6.2
    Medium

    CVE-2022-24725

    Last Modified: 22 Apr 2025

    Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `interpolation` option set to `true`. Other tested shells, Dash and Zsh, are not affected. Depending on how the output of _shescape_ is used, directory traversal may be possible in the application using _shescape_. The issue was patched in version 1.5.1. As a workaround, manually escape all instances of the tilde character (`~`) using `arg.replace(/~/g, "\\~")`.

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22695

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22693

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22694

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22692

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22691

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22690

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22688

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22689

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22687

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    —
    Unknown

    CVE-2021-22686

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 3 Mar 2022
    5.3
    Medium

    CVE-2022-22700

    Last Modified: 21 Nov 2024

    CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant.

    Published: 3 Mar 2022
    9.8
    Critical

    CVE-2022-25125

    Last Modified: 21 Nov 2024

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.

    Published: 3 Mar 2022
    9.8
    Critical

    CVE-2022-23898

    Last Modified: 21 Nov 2024

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.

    Published: 3 Mar 2022
    9.8
    Critical

    CVE-2022-23899

    Last Modified: 21 Nov 2024

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.

    Published: 3 Mar 2022
    5.4
    Medium

    CVE-2022-25138

    Last Modified: 21 Nov 2024

    Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name parameter.

    Published: 3 Mar 2022
    6.1
    Medium

    CVE-2022-0753

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.

    Published: 3 Mar 2022
    4.9
    Medium

    CVE-2021-43774

    Last Modified: 21 Nov 2024

    A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users (domain users, FTP users, etc.) stored on the printer, together with their encrypted passwords. The passwords are protected by a weak cipher, such as ROT13, which requires minimal effort to instantly retrieve the original password, giving the attacker a list of valid domain or FTP usernames and passwords.

    Published: 3 Mar 2022
    7.8
    High

    CVE-2022-22706

    Last Modified: 3 Nov 2025

    Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.

    Published: 3 Mar 2022
    7.8
    High

    CVE-2022-25031

    Last Modified: 21 Nov 2024

    Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.

    Published: 3 Mar 2022
    6.4
    Medium

    CVE-2021-45819

    Last Modified: 21 Nov 2024

    Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level.

    Published: 3 Mar 2022
    6.1
    Medium

    CVE-2021-40637

    Last Modified: 21 Nov 2024

    OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.

    Published: 3 Mar 2022
    7.5
    High

    CVE-2021-40636

    Last Modified: 21 Nov 2024

    OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.

    Published: 3 Mar 2022
    7.5
    High

    CVE-2021-40635

    Last Modified: 21 Nov 2024

    OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.

    Published: 3 Mar 2022
    9.1
    Critical

    CVE-2022-0742

    Last Modified: 21 Apr 2025

    Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

    Published: 3 Mar 2022