CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-23954

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

    Published: 2 Mar 2022
    2.7
    Low

    CVE-2021-46270

    Last Modified: 21 Nov 2024

    JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

    Published: 2 Mar 2022
    4.3
    Medium

    CVE-2021-45074

    Last Modified: 21 Nov 2024

    JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2022-23953

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2022-23956

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-25045

    Last Modified: 21 Nov 2024

    Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

    Published: 2 Mar 2022
    5.4
    Medium

    CVE-2022-22944

    Last Modified: 21 Nov 2024

    VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window.

    Published: 2 Mar 2022
    4.6
    Medium

    CVE-2022-23656

    Last Modified: 23 Apr 2025

    Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent topics page. An attacker could maliciously craft a full name for their account and send messages to a topic with several participants; a victim who then opens an overflow tooltip including this full name on the recent topics page could trigger execution of JavaScript code controlled by the attacker. Users running a Zulip server from the main branch should upgrade from main (2022-03-01 or later) again to deploy this fix.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-23640

    Last Modified: 23 Apr 2025

    Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a patch. There is no known workaround.

    Published: 2 Mar 2022
    6.5
    Medium

    CVE-2021-38268

    Last Modified: 21 Nov 2024

    The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the API.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-23878

    Last Modified: 21 Nov 2024

    seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-25016

    Last Modified: 21 Nov 2024

    Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 2 Mar 2022
    5.4
    Medium

    CVE-2021-43070

    Last Modified: 21 Nov 2024

    Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2022-22350

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 220394.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2021-38996

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213076.

    Published: 2 Mar 2022
    8.8
    High

    CVE-2022-0819

    Last Modified: 21 Nov 2024

    Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

    Published: 2 Mar 2022
    6.5
    Medium

    CVE-2022-24447

    Last Modified: 30 May 2025

    An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-24305

    Last Modified: 21 Nov 2024

    Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.

    Published: 2 Mar 2022
    9.8
    Critical

    CVE-2022-24306

    Last Modified: 21 Nov 2024

    Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

    Published: 2 Mar 2022
    5.3
    Medium

    CVE-2022-23779

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

    Published: 2 Mar 2022
    8.1
    High

    CVE-2022-0829

    Last Modified: 21 Nov 2024

    Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

    Published: 2 Mar 2022
    6.1
    Medium

    CVE-2022-23395

    Last Modified: 21 Nov 2024

    jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).

    Published: 2 Mar 2022
    4.1
    Medium

    CVE-2021-44166

    Last Modified: 21 Nov 2024

    An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and below may allow a remote attacker having already obtained a user's password to access the protected system during the 2FA procedure, even though the deny button is clicked by the legitimate user.

    Published: 2 Mar 2022
    7.8
    High

    CVE-2022-22301

    Last Modified: 21 Nov 2024

    An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized commands by running CLI commands with specifically crafted arguments.

    Published: 2 Mar 2022
    2.8
    Low

    CVE-2022-22303

    Last Modified: 21 Nov 2024

    An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.

    Published: 2 Mar 2022
    6.5
    Medium

    CVE-2022-0577

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

    Published: 2 Mar 2022
    —
    Unknown

    CVE-2022-26038

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Mar 2022
    —
    Unknown

    CVE-2022-25870

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Mar 2022
    —
    Unknown

    CVE-2022-26056

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Mar 2022
    —
    Unknown

    CVE-2022-25909

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Mar 2022
    —
    Unknown

    CVE-2022-26072

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Mar 2022
    —
    Unknown

    CVE-2022-26304

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Mar 2022
    —
    Unknown

    CVE-2022-26037

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 2 Mar 2022
    8.8
    High

    CVE-2022-0824

    Last Modified: 21 Nov 2024

    Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

    Published: 2 Mar 2022
    7.5
    High

    CVE-2022-25634

    Last Modified: 21 Nov 2024

    Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

    Published: 2 Mar 2022
    7.5
    High

    CVE-2022-23648

    Last Modified: 21 Nov 2024

    containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.

    Published: 2 Mar 2022
    5.5
    Medium

    CVE-2021-45863

    Last Modified: 21 Nov 2024

    tsMuxer git-2678966 was discovered to contain a heap-based buffer overflow via the function HevcUnit::updateBits in hevc.cpp.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2021-45860

    Last Modified: 21 Nov 2024

    An integer overflow in DTSStreamReader::findFrame() of tsMuxer git-2678966 allows attackers to cause a Denial of Service (DoS) via a crafted file.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2022-25051

    Last Modified: 21 Nov 2024

    An Off-by-one Error occurs in cmr113_decode of rtl_433 21.12 when decoding a crafted file.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2021-45864

    Last Modified: 21 Nov 2024

    tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2021-45861

    Last Modified: 21 Nov 2024

    There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2022-25050

    Last Modified: 21 Nov 2024

    rtl_433 21.12 was discovered to contain a stack overflow in the function somfy_iohc_decode(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2022-24255

    Last Modified: 21 Nov 2024

    Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2022-24254

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2022-24253

    Last Modified: 21 Nov 2024

    Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2022-24252

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2022-24251

    Last Modified: 21 Nov 2024

    Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2021-41282

    Last Modified: 21 Nov 2024

    diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.

    Published: 1 Mar 2022
    7.5
    High

    CVE-2021-41652

    Last Modified: 21 Nov 2024

    Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2022-25012

    Last Modified: 21 Nov 2024

    Argus Surveillance DVR v4.0 employs weak password encryption.

    Published: 1 Mar 2022