CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-0762

    Last Modified: 24 Feb 2026

    Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.

    Published: 26 Feb 2022
    9.1
    Critical

    CVE-2022-25359

    Last Modified: 21 Nov 2024

    On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.

    Published: 26 Feb 2022
    7.8
    High

    CVE-2022-24986

    Last Modified: 21 Nov 2024

    KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.

    Published: 26 Feb 2022
    5.9
    Medium

    CVE-2020-36516

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.

    Published: 26 Feb 2022
    5.5
    Medium

    CVE-2021-46702

    Last Modified: 21 Nov 2024

    Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished by analyzing RAM memory even several hours after the local user used the product. This occurs because the product doesn't properly free memory.

    Published: 26 Feb 2022
    7.2
    High

    CVE-2022-26149

    Last Modified: 21 Nov 2024

    MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.

    Published: 26 Feb 2022
    7.2
    High

    CVE-2022-21706

    Last Modified: 23 Apr 2025

    Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack where an invitation created in one organization (potentially as a role with elevated permissions) can be used to join any other organization. This bypasses any restrictions on required domains on users' email addresses, may be used to gain access to organizations which are only accessible by invitation, and may be used to gain access with elevated privileges. This issue has been patched in release 4.10. There are no known workarounds for this issue. ### Patches _Has the problem been patched? What versions should users upgrade to?_ ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ ### References _Are there any links users can visit to find out more?_ ### For more information If you have any questions or comments about this advisory, you can discuss them on the [developer community Zulip server](https://zulip.com/developer-community/), or email the [Zulip security team](mailto:[email protected]).

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-25096

    Last Modified: 21 Nov 2024

    Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-25095

    Last Modified: 21 Nov 2024

    Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.

    Published: 25 Feb 2022
    8.8
    High

    CVE-2022-25094

    Last Modified: 21 Nov 2024

    Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.

    Published: 25 Feb 2022
    5.4
    Medium

    CVE-2022-24710

    Last Modified: 23 Apr 2025

    Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-24442

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2022-25259

    Last Modified: 21 Nov 2024

    JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.

    Published: 25 Feb 2022
    9.1
    Critical

    CVE-2022-25260

    Last Modified: 21 Nov 2024

    JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

    Published: 25 Feb 2022
    5.4
    Medium

    CVE-2021-23495

    Last Modified: 21 Nov 2024

    The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2022-25261

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-25262

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-25263

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-25264

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

    Published: 25 Feb 2022
    9.9
    Critical

    CVE-2021-42952

    Last Modified: 21 Nov 2024

    Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-25061

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-25064

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-25062

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-25060

    Last Modified: 21 Nov 2024

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

    Published: 25 Feb 2022
    7.8
    High

    CVE-2021-44132

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2021-37504

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2021-42244

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted title or message in a notification.

    Published: 25 Feb 2022
    —
    Unknown

    CVE-2022-0655

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-40046

    Last Modified: 21 Nov 2024

    PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.

    Published: 25 Feb 2022
    —
    Unknown

    CVE-2022-25019

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-38602. Reason: This candidate is a reservation duplicate of CVE-2021-38602. Notes: All CVE users should reference CVE-2021-38602 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Feb 2022
    7.8
    High

    CVE-2021-40043

    Last Modified: 21 Nov 2024

    The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the device to be visually exploitable and successful triggering of this vulnerability could execute voice commands on the device.

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2021-37103

    Last Modified: 21 Nov 2024

    There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22429

    Last Modified: 21 Nov 2024

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22432

    Last Modified: 21 Nov 2024

    There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22426

    Last Modified: 21 Nov 2024

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22430

    Last Modified: 21 Nov 2024

    There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22431

    Last Modified: 21 Nov 2024

    There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22433

    Last Modified: 21 Nov 2024

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22434

    Last Modified: 21 Nov 2024

    There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

    Published: 25 Feb 2022
    9.1
    Critical

    CVE-2021-22394

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2021-22395

    Last Modified: 21 Nov 2024

    There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2021-22319

    Last Modified: 21 Nov 2024

    There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause integer overflows.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2021-37027

    Last Modified: 21 Nov 2024

    There is a DoS vulnerability in smartphones. Successful exploitation of this vulnerability may affect service integrity.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2021-22489

    Last Modified: 21 Nov 2024

    There is a DoS vulnerability in smartphones. Successful exploitation of this vulnerability may affect service availability.

    Published: 25 Feb 2022
    9.1
    Critical

    CVE-2021-22448

    Last Modified: 21 Nov 2024

    There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files.

    Published: 25 Feb 2022
    7
    High

    CVE-2021-22437

    Last Modified: 21 Nov 2024

    There is a software integer overflow leading to a TOCTOU condition in smartphones. Successful exploitation of this vulnerability may cause random address access.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-22480

    Last Modified: 21 Nov 2024

    The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2021-22479

    Last Modified: 21 Nov 2024

    The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2021-22478

    Last Modified: 21 Nov 2024

    The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may lead to information leakage.

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2021-22441

    Last Modified: 21 Nov 2024

    Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.

    Published: 25 Feb 2022