CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-0528

    Last Modified: 24 Feb 2026

    Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

    Published: 3 Mar 2022
    8.8
    High

    CVE-2021-42950

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability exists in Zepl Notebooks all previous versions before October 25 2021. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new organization by which additional users can be added for various collaboration abilities, which allows malicious user to create new Zepl Notebooks with various languages, contexts, and deployment scenarios. Upon creating a new notebook with specially crafted malicious code, a user can then launch remote code execution.

    Published: 3 Mar 2022
    6.6
    Medium

    CVE-2022-23849

    Last Modified: 21 Nov 2024

    The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.

    Published: 3 Mar 2022
    6.1
    Medium

    CVE-2022-24573

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.

    Published: 3 Mar 2022
    5.4
    Medium

    CVE-2022-24563

    Last Modified: 21 Nov 2024

    In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.

    Published: 3 Mar 2022
    7.4
    High

    CVE-2021-38578

    Last Modified: 3 Nov 2025

    Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

    Published: 3 Mar 2022
    7.8
    High

    CVE-2021-26948

    Last Modified: 21 Nov 2024

    Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.

    Published: 3 Mar 2022
    9.8
    Critical

    CVE-2022-0265

    Last Modified: 21 Nov 2024

    Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

    Published: 3 Mar 2022
    9.8
    Critical

    CVE-2022-0730

    Last Modified: 21 Nov 2024

    Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

    Published: 3 Mar 2022
    9.8
    Critical

    CVE-2022-0841

    Last Modified: 21 Nov 2024

    OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.

    Published: 3 Mar 2022
    5.3
    Medium

    CVE-2022-24723

    Last Modified: 22 Apr 2025

    URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.

    Published: 3 Mar 2022
    7.5
    High

    CVE-2022-24921

    Last Modified: 21 Nov 2024

    regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.

    Published: 3 Mar 2022
    7.8
    High

    CVE-2021-26259

    Last Modified: 21 Nov 2024

    A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.

    Published: 3 Mar 2022
    7.5
    High

    CVE-2022-21716

    Last Modified: 22 Apr 2025

    Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.

    Published: 3 Mar 2022
    8.8
    High

    CVE-2022-24724

    Last Modified: 22 Apr 2025

    cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruption when parsing tables who's marker rows contain more than UINT16_MAX columns. The impact of this heap corruption ranges from Information Leak to Arbitrary Code Execution depending on how and where `cmark-gfm` is used. If `cmark-gfm` is used for rendering remote user controlled markdown, this vulnerability may lead to Remote Code Execution (RCE) in applications employing affected versions of the `cmark-gfm` library. This vulnerability has been patched in the following cmark-gfm versions 0.29.0.gfm.3 and 0.28.3.gfm.21. A workaround is available. The vulnerability exists in the table markdown extensions of cmark-gfm. Disabling the table extension will prevent this vulnerability from being triggered.

    Published: 3 Mar 2022
    10
    Critical

    CVE-2022-22947

    Last Modified: 30 Oct 2025

    In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

    Published: 3 Mar 2022
    8.8
    High

    CVE-2022-22909

    Last Modified: 21 Nov 2024

    HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.

    Published: 2 Mar 2022
    5.3
    Medium

    CVE-2022-25146

    Last Modified: 21 Nov 2024

    The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.

    Published: 2 Mar 2022
    5.4
    Medium

    CVE-2021-38269

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the output of a Gogo Shell command.

    Published: 2 Mar 2022
    7.8
    High

    CVE-2021-44343

    Last Modified: 21 Nov 2024

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_read_data() in "/ok_png.c".

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-25089

    Last Modified: 21 Nov 2024

    Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.

    Published: 2 Mar 2022
    5.4
    Medium

    CVE-2021-38267

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_portlet_BlogsAdminPortlet_title and _com_liferay_blogs_web_portlet_BlogsAdminPortlet_subtitle parameter.

    Published: 2 Mar 2022
    7.8
    High

    CVE-2021-44335

    Last Modified: 21 Nov 2024

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_transform_scanline() in "/ok_png.c:533".

    Published: 2 Mar 2022
    6.1
    Medium

    CVE-2021-38263

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.

    Published: 2 Mar 2022
    8.1
    High

    CVE-2022-25471

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.

    Published: 2 Mar 2022
    6.1
    Medium

    CVE-2021-38264

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.

    Published: 2 Mar 2022
    5.4
    Medium

    CVE-2021-38265

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.

    Published: 2 Mar 2022
    7.5
    High

    CVE-2021-38266

    Last Modified: 21 Nov 2024

    The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.

    Published: 2 Mar 2022
    8.1
    High

    CVE-2022-24722

    Last Modified: 23 Apr 2025

    VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulnerability that has the potential to impact anyone using translations with the view_component gem. Data received via user input and passed as an interpolation argument to the `translate` method is not properly sanitized before display. Versions 2.31.2 and 2.49.1 have been released and fully mitigate the vulnerability. As a workaround, avoid passing user input to the `translate` function, or sanitize the inputs before passing them.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-26171

    Last Modified: 21 Nov 2024

    Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-26170

    Last Modified: 21 Nov 2024

    Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-26169

    Last Modified: 21 Nov 2024

    Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-25399

    Last Modified: 21 Nov 2024

    Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-25398

    Last Modified: 21 Nov 2024

    Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-25396

    Last Modified: 21 Nov 2024

    Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.

    Published: 2 Mar 2022
    9.6
    Critical

    CVE-2022-25395

    Last Modified: 21 Nov 2024

    Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.

    Published: 2 Mar 2022
    7.5
    High

    CVE-2022-25393

    Last Modified: 21 Nov 2024

    Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-25394

    Last Modified: 21 Nov 2024

    Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php.

    Published: 2 Mar 2022
    7.8
    High

    CVE-2022-25115

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file.

    Published: 2 Mar 2022
    6.1
    Medium

    CVE-2022-25114

    Last Modified: 21 Nov 2024

    Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under register.php.

    Published: 2 Mar 2022
    7.8
    High

    CVE-2021-23180

    Last Modified: 21 Nov 2024

    A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.

    Published: 2 Mar 2022
    7.8
    High

    CVE-2021-23191

    Last Modified: 21 Nov 2024

    A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.

    Published: 2 Mar 2022
    7.8
    High

    CVE-2021-23206

    Last Modified: 21 Nov 2024

    A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

    Published: 2 Mar 2022
    6.1
    Medium

    CVE-2021-41003

    Last Modified: 21 Nov 2024

    Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.

    Published: 2 Mar 2022
    8.1
    High

    CVE-2021-41002

    Last Modified: 21 Nov 2024

    Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.

    Published: 2 Mar 2022
    8.8
    High

    CVE-2021-41000

    Last Modified: 21 Nov 2024

    Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below. Aruba has released upgrades for Aruba AOS-CX devices that address these security vulnerabilities.

    Published: 2 Mar 2022
    8.8
    High

    CVE-2021-41001

    Last Modified: 21 Nov 2024

    An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below. Aruba has released upgrades for Aruba AOS-CX devices that address this security vulnerability.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2022-23957

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2022-23958

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2022-23955

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

    Published: 2 Mar 2022