CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2021-29217

    Last Modified: 21 Nov 2024

    A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.

    Published: 24 Feb 2022
    6.1
    Medium

    CVE-2021-29216

    Last Modified: 21 Nov 2024

    A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.

    Published: 24 Feb 2022
    5.5
    Medium

    CVE-2021-43745

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerabilty exists in Trilium Notes 0.48.6 in the setupPage function

    Published: 24 Feb 2022
    6.5
    Medium

    CVE-2021-44665

    Last Modified: 21 Nov 2024

    A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php.

    Published: 24 Feb 2022
    8.8
    High

    CVE-2021-44664

    Last Modified: 21 Nov 2024

    An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.

    Published: 24 Feb 2022
    8.8
    High

    CVE-2022-24709

    Last Modified: 23 Apr 2025

    @awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to upgrade to version 3.0.367 or later. There are no known workarounds for this issue.

    Published: 24 Feb 2022
    9.8
    Critical

    CVE-2021-44663

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php.

    Published: 24 Feb 2022
    6.1
    Medium

    CVE-2021-44662

    Last Modified: 21 Nov 2024

    A Site Scripting (XSS) vulnerability exists in the Xerte Project Xerte through 3.8.4 via the link parameter in print.php.

    Published: 24 Feb 2022
    6.5
    Medium

    CVE-2020-10636

    Last Modified: 16 Apr 2025

    Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.

    Published: 24 Feb 2022
    10
    Critical

    CVE-2020-10640

    Last Modified: 16 Apr 2025

    Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

    Published: 24 Feb 2022
    8.8
    High

    CVE-2020-10632

    Last Modified: 16 Apr 2025

    Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.

    Published: 24 Feb 2022
    7.5
    High

    CVE-2021-4021

    Last Modified: 21 Nov 2024

    A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.

    Published: 24 Feb 2022
    4.3
    Medium

    CVE-2020-10635

    Last Modified: 16 Apr 2025

    Simulation models for KUKA.Sim Pro version 3.1 are hosted by a server maintained by KUKA. When these devices request a model, the server transmits the model in plaintext.

    Published: 24 Feb 2022
    7.8
    High

    CVE-2022-0546

    Last Modified: 21 Nov 2024

    A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.

    Published: 24 Feb 2022
    7.8
    High

    CVE-2022-0545

    Last Modified: 21 Nov 2024

    An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.

    Published: 24 Feb 2022
    5.5
    Medium

    CVE-2022-0544

    Last Modified: 21 Nov 2024

    An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.

    Published: 24 Feb 2022
    5.5
    Medium

    CVE-2020-14480

    Last Modified: 17 Apr 2025

    Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.

    Published: 24 Feb 2022
    7.8
    High

    CVE-2020-14481

    Last Modified: 17 Apr 2025

    The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the user’s operating system and certain components of FactoryTalk View SE.

    Published: 24 Feb 2022
    7.1
    High

    CVE-2020-14478

    Last Modified: 17 Apr 2025

    A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

    Published: 24 Feb 2022
    7.2
    High

    CVE-2022-25307

    Last Modified: 7 Feb 2025

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.

    Published: 24 Feb 2022
    7.2
    High

    CVE-2022-25305

    Last Modified: 7 Feb 2025

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.

    Published: 24 Feb 2022
    7.2
    High

    CVE-2022-25306

    Last Modified: 31 Jan 2025

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.

    Published: 24 Feb 2022
    9.8
    Critical

    CVE-2022-25149

    Last Modified: 31 Jan 2025

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

    Published: 24 Feb 2022
    6.1
    Medium

    CVE-2022-0683

    Last Modified: 31 Jan 2025

    The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the settings parameter found in the ~/includes/Traits/Helper.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 5.0.8.

    Published: 24 Feb 2022
    9.8
    Critical

    CVE-2022-0651

    Last Modified: 31 Jan 2025

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

    Published: 24 Feb 2022
    6.1
    Medium

    CVE-2022-0710

    Last Modified: 31 Jan 2025

    The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter.

    Published: 24 Feb 2022
    6.1
    Medium

    CVE-2022-0653

    Last Modified: 31 Jan 2025

    The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the site_url parameter found in the ~/assets/misc/fallback-page.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a user clicks on a specially crafted link by an attacker. This affects versions up to and including 3.6.1.

    Published: 24 Feb 2022
    5.6
    Medium

    CVE-2022-23104

    Last Modified: 16 Apr 2025

    WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the program Operator Workspace directory, which holds DLL files and executables. A low-privilege attacker could write a malicious DLL file to the Operator Workspace directory to achieve privilege escalation and the permissions of the user running the program.

    Published: 24 Feb 2022
    5.6
    Medium

    CVE-2022-23922

    Last Modified: 16 Apr 2025

    WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the Program Announcer directory and elevate permissions whenever the program is executed.

    Published: 24 Feb 2022
    6.1
    Medium

    CVE-2020-14502

    Last Modified: 17 Apr 2025

    The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.

    Published: 24 Feb 2022
    5.3
    Medium

    CVE-2020-14504

    Last Modified: 17 Apr 2025

    The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuration settings.

    Published: 24 Feb 2022
    6.5
    Medium

    CVE-2022-23135

    Last Modified: 21 Nov 2024

    There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.

    Published: 24 Feb 2022
    9.8
    Critical

    CVE-2022-25004

    Last Modified: 21 Nov 2024

    Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.

    Published: 24 Feb 2022
    7.8
    High

    CVE-2022-24232

    Last Modified: 21 Nov 2024

    A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 24 Feb 2022
    9.8
    Critical

    CVE-2022-25003

    Last Modified: 21 Nov 2024

    Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.

    Published: 24 Feb 2022
    4.3
    Medium

    CVE-2022-0812

    Last Modified: 13 Feb 2025

    An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information.

    Published: 24 Feb 2022
    4.3
    Medium

    CVE-2022-22349

    Last Modified: 21 Nov 2024

    IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.

    Published: 24 Feb 2022
    5.4
    Medium

    CVE-2021-39038

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.

    Published: 24 Feb 2022
    5.5
    Medium

    CVE-2021-38995

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213073.

    Published: 24 Feb 2022
    5.5
    Medium

    CVE-2021-38994

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 213072.

    Published: 24 Feb 2022
    6.1
    Medium

    CVE-2022-22793

    Last Modified: 21 Nov 2024

    Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.

    Published: 24 Feb 2022
    6.8
    Medium

    CVE-2022-22794

    Last Modified: 21 Nov 2024

    Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and by doing that, the attacker can run Remote Code Execution in one liner.

    Published: 24 Feb 2022
    7.5
    High

    CVE-2022-0732

    Last Modified: 21 Nov 2024

    The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.

    Published: 24 Feb 2022
    6.5
    Medium

    CVE-2022-24687

    Last Modified: 21 Nov 2024

    HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

    Published: 24 Feb 2022
    —
    Unknown

    CVE-2021-3940

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 24 Feb 2022
    —
    Unknown

    CVE-2021-3937

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 24 Feb 2022
    —
    Unknown

    CVE-2021-3893

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 24 Feb 2022
    —
    Unknown

    CVE-2021-3887

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 24 Feb 2022
    —
    Unknown

    CVE-2021-3886

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 24 Feb 2022
    —
    Unknown

    CVE-2021-3884

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none

    Published: 24 Feb 2022