CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-36166

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.

    Published: 1 Mar 2022
    8.1
    High

    CVE-2021-36171

    Last Modified: 21 Nov 2024

    The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2022-22321

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protection. IBM X-Force ID: 218368.

    Published: 1 Mar 2022
    5.4
    Medium

    CVE-2021-38986

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 212942.

    Published: 1 Mar 2022
    4.4
    Medium

    CVE-2021-38955

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2020-4925

    Last Modified: 21 Nov 2024

    A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to service other requests. IBM X-Force ID: 191599.

    Published: 1 Mar 2022
    7.5
    High

    CVE-2022-23387

    Last Modified: 21 Nov 2024

    An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment Update field.

    Published: 1 Mar 2022
    7.2
    High

    CVE-2021-44238

    Last Modified: 21 Nov 2024

    AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,

    Published: 1 Mar 2022
    6.1
    Medium

    CVE-2021-46387

    Last Modified: 21 Nov 2024

    ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2022-23380

    Last Modified: 21 Nov 2024

    There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.

    Published: 1 Mar 2022
    7.5
    High

    CVE-2022-23377

    Last Modified: 21 Nov 2024

    Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.

    Published: 1 Mar 2022
    4.6
    Medium

    CVE-2021-44747

    Last Modified: 21 Nov 2024

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the Fmlib component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.

    Published: 1 Mar 2022
    7.5
    High

    CVE-2022-0777

    Last Modified: 21 Nov 2024

    Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

    Published: 1 Mar 2022
    6.1
    Medium

    CVE-2022-0776

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.

    Published: 1 Mar 2022
    9.8
    Critical

    CVE-2021-4039

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.

    Published: 1 Mar 2022
    6.5
    Medium

    CVE-2021-35036

    Last Modified: 21 Nov 2024

    A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.

    Published: 1 Mar 2022
    7.8
    High

    CVE-2021-43619

    Last Modified: 5 Jun 2026

    Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.

    Published: 1 Mar 2022
    4.3
    Medium

    CVE-2022-24446

    Last Modified: 30 May 2025

    An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.

    Published: 1 Mar 2022
    7.7
    High

    CVE-2022-22262

    Last Modified: 21 Nov 2024

    ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since this function does not validate the path before deletion, an unauthenticated local attacker can create an unexpected symbolic link to system file path, to delete arbitrary system files and disrupt system service.

    Published: 1 Mar 2022
    9.8
    Critical

    CVE-2020-12775

    Last Modified: 21 Nov 2024

    Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2021-44962

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability exists in the GCode::extrude() functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A specially crafted stl file could lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2021-44961

    Last Modified: 21 Nov 2024

    A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2021-42951

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new, specially crafted Algorithm and subsequently launch remote code execution with their desired result.

    Published: 1 Mar 2022
    9.1
    Critical

    CVE-2021-42767

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.

    Published: 1 Mar 2022
    5.4
    Medium

    CVE-2022-25022

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.

    Published: 1 Mar 2022
    5.4
    Medium

    CVE-2022-25020

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.

    Published: 1 Mar 2022
    8.8
    High

    CVE-2022-25018

    Last Modified: 21 Nov 2024

    Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

    Published: 1 Mar 2022
    5.4
    Medium

    CVE-2022-26332

    Last Modified: 21 Nov 2024

    Cipi 3.1.15 allows Add Server stored XSS via the /api/servers name field.

    Published: 1 Mar 2022
    9.8
    Critical

    CVE-2022-24720

    Last Modified: 22 Apr 2025

    image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell commands. This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. The vulnerability has been fixed in version 1.12.2 of image_processing. As a workaround, users who process based on user input should always sanitize the user input by allowing only a constrained set of operations.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2022-0865

    Last Modified: 21 Nov 2024

    Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.

    Published: 1 Mar 2022
    5.5
    Medium

    CVE-2022-1056

    Last Modified: 21 Nov 2024

    Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.

    Published: 1 Mar 2022
    5.9
    Medium

    CVE-2023-4813

    Last Modified: 11 Nov 2025

    A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

    Published: 1 Mar 2022
    4.6
    Medium

    CVE-2022-0743

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2022-25413

    Last Modified: 21 Nov 2024

    Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.

    Published: 28 Feb 2022
    8.1
    High

    CVE-2022-25412

    Last Modified: 21 Nov 2024

    Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.

    Published: 28 Feb 2022
    9.8
    Critical

    CVE-2022-25411

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2022-25409

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2022-25410

    Last Modified: 21 Nov 2024

    Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2022-25407

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2022-25408

    Last Modified: 21 Nov 2024

    Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2022-25029

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-25096. Reason: This candidate is a duplicate of CVE-2022-25096. Notes: All CVE users should reference CVE-2022-25096 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-25028

    Last Modified: 21 Nov 2024

    Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-23907

    Last Modified: 21 Nov 2024

    CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.

    Published: 28 Feb 2022
    7.2
    High

    CVE-2022-23906

    Last Modified: 21 Nov 2024

    CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36820

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36819

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36817

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36818

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36816

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36814

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022