CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2021-26617

    Last Modified: 21 Nov 2024

    This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-21798

    Last Modified: 16 Apr 2025

    The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-23921

    Last Modified: 16 Apr 2025

    Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already running a project, and the server is licensed for multiple projects.

    Published: 25 Feb 2022
    7.8
    High

    CVE-2022-25170

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code

    Published: 25 Feb 2022
    7.8
    High

    CVE-2022-21209

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

    Published: 25 Feb 2022
    7.8
    High

    CVE-2022-23985

    Last Modified: 16 Apr 2025

    The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

    Published: 25 Feb 2022
    5.9
    Medium

    CVE-2022-0615

    Last Modified: 21 Nov 2024

    Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-service condition on the system.

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2021-38993

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daemon to cause a denial of service. IBM X-Force ID: 212962.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-45977

    Last Modified: 21 Nov 2024

    JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

    Published: 25 Feb 2022
    5.4
    Medium

    CVE-2022-24347

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

    Published: 25 Feb 2022
    7.8
    High

    CVE-2022-24346

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

    Published: 25 Feb 2022
    7.8
    High

    CVE-2022-24345

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

    Published: 25 Feb 2022
    5.4
    Medium

    CVE-2022-24344

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

    Published: 25 Feb 2022
    4.3
    Medium

    CVE-2022-24343

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

    Published: 25 Feb 2022
    8.8
    High

    CVE-2022-24342

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-24341

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-24340

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

    Published: 25 Feb 2022
    5.4
    Medium

    CVE-2022-24339

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2022-24338

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.

    Published: 25 Feb 2022
    6.5
    Medium

    CVE-2022-24337

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

    Published: 25 Feb 2022
    5.3
    Medium

    CVE-2022-24336

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.

    Published: 25 Feb 2022
    8.1
    High

    CVE-2022-24335

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.

    Published: 25 Feb 2022
    5.3
    Medium

    CVE-2022-24334

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

    Published: 25 Feb 2022
    6.5
    Medium

    CVE-2022-24333

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.

    Published: 25 Feb 2022
    5.3
    Medium

    CVE-2022-24332

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2022-24331

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2022-24330

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.

    Published: 25 Feb 2022
    6.5
    Medium

    CVE-2022-24328

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-24327

    Last Modified: 21 Nov 2024

    In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-25374

    Last Modified: 21 Nov 2024

    HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.

    Published: 25 Feb 2022
    5.3
    Medium

    CVE-2022-24594

    Last Modified: 21 Nov 2024

    In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.

    Published: 25 Feb 2022
    5.4
    Medium

    CVE-2022-24612

    Last Modified: 21 Nov 2024

    An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.

    Published: 25 Feb 2022
    7.5
    High

    CVE-2022-0247

    Last Modified: 21 Apr 2025

    An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.

    Published: 25 Feb 2022
    5
    Medium

    CVE-2022-25328

    Last Modified: 21 Apr 2025

    The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2022-25327

    Last Modified: 21 Apr 2025

    The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2022-25326

    Last Modified: 21 Apr 2025

    fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.

    Published: 25 Feb 2022
    4.3
    Medium

    CVE-2022-0746

    Last Modified: 21 Nov 2024

    Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2022-24948

    Last Modified: 21 Nov 2024

    A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.2 or later.

    Published: 25 Feb 2022
    8.8
    High

    CVE-2022-24947

    Last Modified: 21 Nov 2024

    Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.

    Published: 25 Feb 2022
    8.8
    High

    CVE-2022-24288

    Last Modified: 21 Nov 2024

    In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

    Published: 25 Feb 2022
    6.1
    Medium

    CVE-2021-45229

    Last Modified: 21 Nov 2024

    It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.

    Published: 25 Feb 2022
    5.3
    Medium

    CVE-2021-34361

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later

    Published: 25 Feb 2022
    6.9
    Medium

    CVE-2021-34359

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later

    Published: 25 Feb 2022
    8.1
    High

    CVE-2022-23835

    Last Modified: 21 Nov 2024

    The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design) not displayed to the victim within the AOSP SMS/MMS messaging application. (Often, the IMAP credentials are usable to listen to voice mail messages sent before the vulnerability was exploited, in addition to new ones.) NOTE: some vendors characterize this as not a "concrete and exploitable risk.

    Published: 25 Feb 2022
    5.3
    Medium

    CVE-2022-24329

    Last Modified: 21 Nov 2024

    In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.

    Published: 25 Feb 2022
    5.5
    Medium

    CVE-2022-3599

    Last Modified: 7 May 2025

    LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.

    Published: 25 Feb 2022
    9.8
    Critical

    CVE-2021-39363

    Last Modified: 21 Nov 2024

    Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.

    Published: 24 Feb 2022
    7.5
    High

    CVE-2021-39364

    Last Modified: 21 Nov 2024

    Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.

    Published: 24 Feb 2022
    7.2
    High

    CVE-2021-29220

    Last Modified: 21 Nov 2024

    Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12. These vulnerabilities could be exploited by a highly privileged user to remotely execute code that could lead to a loss of confidentiality, integrity, and availability. HPE has provided a software update to resolve this vulnerability in HPE iLO Amplifier Pack.

    Published: 24 Feb 2022
    5.3
    Medium

    CVE-2022-23701

    Last Modified: 21 Nov 2024

    A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver, causing it to respond with a redirect to an attacker-controlled domain. HPE has provided a firmware update to resolve this vulnerability in HPE Integrated Lights-Out 4 (iLO 4).

    Published: 24 Feb 2022