CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2021-36815

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36813

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36812

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36811

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-36810

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27000

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27016

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27015

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27013

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27012

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27011

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27010

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27009

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    —
    Unknown

    CVE-2021-27008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. Notes: none

    Published: 28 Feb 2022
    9.8
    Critical

    CVE-2021-45414

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.

    Published: 28 Feb 2022
    8.1
    High

    CVE-2021-41112

    Last Modified: 23 Apr 2025

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing calendars could cause Scheduled Jobs to execute, or not execute on desired calendar days. Severity depends on trust level of authenticated users and impact of running or not running scheduled jobs on days governed by calendar definitions. Version 3.4.5 contains a patch for this issue. There are currently no known workarounds.

    Published: 28 Feb 2022
    6.4
    Medium

    CVE-2021-41111

    Last Modified: 23 Apr 2025

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed webhook tokens to trigger webhooks. Severity depends on trust level of authenticated users and whether any webhooks exist that trigger sensitive actions. There are patches for this vulnerability in versions 3.4.5 and 3.3.15. There are currently no known workarounds.

    Published: 28 Feb 2022
    5.4
    Medium

    CVE-2022-25015

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-25014

    Last Modified: 21 Nov 2024

    Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-25013

    Last Modified: 21 Nov 2024

    Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.

    Published: 28 Feb 2022
    7.5
    High

    CVE-2020-22845

    Last Modified: 21 Nov 2024

    A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests.

    Published: 28 Feb 2022
    7.5
    High

    CVE-2020-22844

    Last Modified: 21 Nov 2024

    A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.

    Published: 28 Feb 2022
    7.8
    High

    CVE-2022-26181

    Last Modified: 21 Nov 2024

    Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

    Published: 28 Feb 2022
    8.8
    High

    CVE-2022-25023

    Last Modified: 21 Nov 2024

    Audio File commit 004065d was discovered to contain a heap-buffer overflow in the function fouBytesToInt():AudioFile.h.

    Published: 28 Feb 2022
    5.3
    Medium

    CVE-2022-26315

    Last Modified: 21 Nov 2024

    qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.

    Published: 28 Feb 2022
    7.8
    High

    CVE-2021-44331

    Last Modified: 21 Nov 2024

    ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().

    Published: 28 Feb 2022
    7.8
    High

    CVE-2021-44342

    Last Modified: 21 Nov 2024

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok_png.c:494".

    Published: 28 Feb 2022
    6.3
    Medium

    CVE-2022-24712

    Last Modified: 23 Apr 2025

    CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attackers to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism. Users should upgrade to version 4.1.9. There are workarounds for this vulnerability, but users will still need to code as these after upgrading to v4.1.9. Otherwise, the CSRF protection may be bypassed. If auto-routing is enabled, check the request method in the controller method before processing. If auto-routing is disabled, either avoid using `$routes->add()` and instead use HTTP verbs in routes; or check the request method in the controller method before processing.

    Published: 28 Feb 2022
    7.8
    High

    CVE-2021-44340

    Last Modified: 21 Nov 2024

    David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_jpg_generate_huffman_table() in "/ok_jpg.c:403".

    Published: 28 Feb 2022
    9.4
    Critical

    CVE-2022-24711

    Last Modified: 23 Apr 2025

    CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for this vulnerability.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-26158

    Last Modified: 21 Nov 2024

    An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.

    Published: 28 Feb 2022
    5.3
    Medium

    CVE-2022-26157

    Last Modified: 21 Nov 2024

    An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected by the Secure flag. This makes it prone to interception by an attacker if traffic is sent over unencrypted channels.

    Published: 28 Feb 2022
    7.8
    High

    CVE-2021-44339

    Last Modified: 21 Nov 2024

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_transform_scanline() in "/ok_png.c:712".

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-26156

    Last Modified: 21 Nov 2024

    An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form action. Form-action hijacking vulnerabilities arise when an application places user-supplied input into the action URL of an HTML form. An attacker can use this vulnerability to construct a URL that, if visited by another application user, will modify the action URL of a form to point to the attacker's server.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-26155

    Last Modified: 21 Nov 2024

    An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload in the SAMLResponse parameter of the HTTP request body.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-25642

    Last Modified: 21 Nov 2024

    Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution.

    Published: 28 Feb 2022
    7.8
    High

    CVE-2021-44334

    Last Modified: 21 Nov 2024

    David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .

    Published: 28 Feb 2022
    9.8
    Critical

    CVE-2021-43086

    Last Modified: 21 Nov 2024

    ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in "/Source/astcenc_compress_symbolic.cpp".

    Published: 28 Feb 2022
    7.5
    High

    CVE-2022-24685

    Last Modified: 21 Nov 2024

    HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-24572

    Last Modified: 21 Nov 2024

    Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Username Field). To exploit this Vulnerability, an admin views the registered user details.

    Published: 28 Feb 2022
    9.8
    Critical

    CVE-2022-24571

    Last Modified: 21 Nov 2024

    Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.

    Published: 28 Feb 2022
    5.9
    Medium

    CVE-2022-0552

    Last Modified: 21 Nov 2024

    A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.

    Published: 28 Feb 2022
    9.1
    Critical

    CVE-2022-0768

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-23988

    Last Modified: 21 Nov 2024

    The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

    Published: 28 Feb 2022
    4.8
    Medium

    CVE-2022-23987

    Last Modified: 21 Nov 2024

    The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 28 Feb 2022
    6.1
    Medium

    CVE-2022-23912

    Last Modified: 21 Nov 2024

    The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting

    Published: 28 Feb 2022
    7.2
    High

    CVE-2022-23911

    Last Modified: 21 Nov 2024

    The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

    Published: 28 Feb 2022
    9.8
    Critical

    CVE-2022-0412

    Last Modified: 21 Nov 2024

    The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks

    Published: 28 Feb 2022
    8.8
    High

    CVE-2022-0411

    Last Modified: 21 Nov 2024

    The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

    Published: 28 Feb 2022