CVE-2022-26123
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26039
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-21224
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-25968
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26053
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-25920
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-25997
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26031
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26339
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26347
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26055
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26418
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26027
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-25889
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-25957
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26416
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26058
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-26087
Last Modified: 7 Nov 2023This candidate was in a CNA pool that was not assigned to any issues during 2022.
CVE-2022-23397
Last Modified: 21 Nov 2024The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data sent in through a URL parameter. This leads to a Reflected Cross-Site Scripting vulnerability. NOTE: the vendor disputes this because the ado.im reference has "no clear steps of reproduction."
CVE-2022-26336
Last Modified: 21 Nov 2024A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
CVE-2022-0853
Last Modified: 21 Nov 2024A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
CVE-2022-22943
Last Modified: 21 Nov 2024VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.
CVE-2022-25220
Last Modified: 21 Nov 2024PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding.
CVE-2022-23052
Last Modified: 21 Nov 2024PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application.
CVE-2022-23051
Last Modified: 21 Nov 2024PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter.
CVE-2022-24725
Last Modified: 22 Apr 2025Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `interpolation` option set to `true`. Other tested shells, Dash and Zsh, are not affected. Depending on how the output of _shescape_ is used, directory traversal may be possible in the application using _shescape_. The issue was patched in version 1.5.1. As a workaround, manually escape all instances of the tilde character (`~`) using `arg.replace(/~/g, "\\~")`.
CVE-2021-22695
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22693
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22694
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22692
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22691
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22690
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22688
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22689
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22687
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2021-22686
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none
CVE-2022-22700
Last Modified: 21 Nov 2024CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant.
CVE-2022-25125
Last Modified: 21 Nov 2024MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
CVE-2022-23898
Last Modified: 21 Nov 2024MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
CVE-2022-23899
Last Modified: 21 Nov 2024MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
CVE-2022-25138
Last Modified: 21 Nov 2024Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name parameter.
CVE-2022-0753
Last Modified: 21 Nov 2024Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
CVE-2021-43774
Last Modified: 21 Nov 2024A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to the administrative web interface of a printer (e.g., by using the default credentials) can download the address book file, which contains the list of users (domain users, FTP users, etc.) stored on the printer, together with their encrypted passwords. The passwords are protected by a weak cipher, such as ROT13, which requires minimal effort to instantly retrieve the original password, giving the attacker a list of valid domain or FTP usernames and passwords.
CVE-2022-22706
Last Modified: 3 Nov 2025Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
CVE-2022-25031
Last Modified: 21 Nov 2024Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2021-45819
Last Modified: 21 Nov 2024Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level.
CVE-2021-40637
Last Modified: 21 Nov 2024OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.
CVE-2021-40636
Last Modified: 21 Nov 2024OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
CVE-2021-40635
Last Modified: 21 Nov 2024OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
CVE-2022-0742
Last Modified: 21 Apr 2025Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.
