CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2022-23651

    Last Modified: 23 Apr 2025

    b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK version 1.14.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. SDK users of the SqliteAccountInfo format are vulnerable while users of the InMemoryAccountInfo format are safe. The SqliteAccountInfo saves API keys (and bucket name-to-id mapping) in a local database file ($XDG_CONFIG_HOME/b2/account_info, ~/.b2_account_info or a user-defined path). When first created, the file is world readable and is (typically a few milliseconds) later altered to be private to the user. If the directory containing the file is readable by a local attacker then during the brief period between file creation and permission modification, a local attacker can race to open the file and maintain a handle to it. This allows the local attacker to read the contents after the file after the sensitive information has been saved to it. Consumers of this SDK who rely on it to save data using SqliteAccountInfo class should upgrade to the latest version of the SDK. Those who believe a local user might have opened a handle using this race condition, should remove the affected database files and regenerate all application keys. Users should upgrade to b2-sdk-python 1.14.1 or later.

    Published: 23 Feb 2022
    5.9
    Medium

    CVE-2022-24409

    Last Modified: 21 Nov 2024

    Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected system. Only customers with active BSAFE maintenance contracts can receive details about this vulnerability. Public disclosure of the vulnerability details will be shared at a later date.

    Published: 23 Feb 2022
    9.8
    Critical

    CVE-2022-25405

    Last Modified: 21 Nov 2024

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter.

    Published: 23 Feb 2022
    9.1
    Critical

    CVE-2022-25098

    Last Modified: 21 Nov 2024

    ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.

    Published: 23 Feb 2022
    7.8
    High

    CVE-2022-25099

    Last Modified: 21 Nov 2024

    A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 23 Feb 2022
    7.8
    High

    CVE-2022-25101

    Last Modified: 21 Nov 2024

    A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 23 Feb 2022
    7.5
    High

    CVE-2022-25104

    Last Modified: 21 Nov 2024

    HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.

    Published: 23 Feb 2022
    7.5
    High

    CVE-2022-25401

    Last Modified: 21 Nov 2024

    The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.

    Published: 23 Feb 2022
    9.1
    Critical

    CVE-2022-25402

    Last Modified: 21 Nov 2024

    An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.

    Published: 23 Feb 2022
    9.8
    Critical

    CVE-2022-25403

    Last Modified: 21 Nov 2024

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.

    Published: 23 Feb 2022
    9.8
    Critical

    CVE-2022-25404

    Last Modified: 21 Nov 2024

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.

    Published: 23 Feb 2022
    9.8
    Critical

    CVE-2022-25406

    Last Modified: 21 Nov 2024

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter.

    Published: 23 Feb 2022
    7.5
    High

    CVE-2021-45746

    Last Modified: 21 Nov 2024

    A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java.

    Published: 23 Feb 2022
    9.8
    Critical

    CVE-2021-44550

    Last Modified: 21 Nov 2024

    An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).

    Published: 23 Feb 2022
    9.1
    Critical

    CVE-2021-4070

    Last Modified: 21 Nov 2024

    Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.

    Published: 23 Feb 2022
    7.5
    High

    CVE-2022-22336

    Last Modified: 21 Nov 2024

    IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.

    Published: 23 Feb 2022
    6.5
    Medium

    CVE-2022-22333

    Last Modified: 21 Nov 2024

    IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a buffer overflow, due to the Jetty based GUI in the Secure Zone not properly validating the sizes of the form content and/or HTTP headers submitted. A local attacker positioned inside the Secure Zone could submit a specially crafted HTTP request to disrupt service. IBM X-Force ID: 219133.

    Published: 23 Feb 2022
    9.8
    Critical

    CVE-2021-44610

    Last Modified: 21 Nov 2024

    Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.

    Published: 23 Feb 2022
    7.2
    High

    CVE-2022-21705

    Last Modified: 23 Apr 2025

    Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to bypass `cms.safe_mode` / `cms.enableSafeMode` in order to execute arbitrary code. This issue only affects admin panels that rely on safe mode and restricted permissions. To exploit this vulnerability, an attacker must first have access to the backend area. The issue has been patched in Build 474 (v1.0.474) and v1.1.10. Users unable to upgrade should apply https://github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe to your installation manually.

    Published: 23 Feb 2022
    5.4
    Medium

    CVE-2021-44608

    Last Modified: 21 Nov 2024

    Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.

    Published: 23 Feb 2022
    5.4
    Medium

    CVE-2021-44607

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.

    Published: 23 Feb 2022
    6.5
    Medium

    CVE-2022-0731

    Last Modified: 21 Nov 2024

    Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

    Published: 23 Feb 2022
    4.8
    Medium

    CVE-2021-43724

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a SGV file.

    Published: 23 Feb 2022
    8.6
    High

    CVE-2022-20623

    Last Modified: 21 Nov 2024

    A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is due to a logic error in the BFD rate limiter functionality. An attacker could exploit this vulnerability by sending a crafted stream of traffic through the device. A successful exploit could allow the attacker to cause BFD traffic to be dropped, resulting in BFD session flaps. BFD session flaps can cause route instability and dropped traffic, resulting in a denial of service (DoS) condition. This vulnerability applies to both IPv4 and IPv6 traffic.

    Published: 23 Feb 2022
    8.6
    High

    CVE-2022-20624

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of incoming CFSoIP packets. An attacker could exploit this vulnerability by sending crafted CFSoIP packets to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

    Published: 23 Feb 2022
    4.3
    Medium

    CVE-2022-20625

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of Cisco Discovery Protocol messages that are processed by the Cisco Discovery Protocol service. An attacker could exploit this vulnerability by sending a series of malicious Cisco Discovery Protocol messages to an affected device. A successful exploit could allow the attacker to cause the Cisco Discovery Protocol service to fail and restart. In rare conditions, repeated failures of the process could occur, which could cause the entire device to restart.

    Published: 23 Feb 2022
    8.8
    High

    CVE-2022-20650

    Last Modified: 21 Nov 2024

    A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. Note: The NX-API feature is disabled by default.

    Published: 23 Feb 2022
    5.5
    Medium

    CVE-2022-0476

    Last Modified: 21 Nov 2024

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

    Published: 23 Feb 2022
    7.5
    High

    CVE-2022-0711

    Last Modified: 21 Nov 2024

    A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

    Published: 23 Feb 2022
    5.4
    Medium

    CVE-2022-24620

    Last Modified: 21 Nov 2024

    Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In this way, admin can steal webmaster's cookies to get the webmaster's access.

    Published: 23 Feb 2022
    5.4
    Medium

    CVE-2022-0727

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

    Published: 23 Feb 2022
    5.4
    Medium

    CVE-2022-24566

    Last Modified: 21 Nov 2024

    In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).

    Published: 23 Feb 2022
    6.5
    Medium

    CVE-2022-0724

    Last Modified: 21 Nov 2024

    Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

    Published: 23 Feb 2022
    6.5
    Medium

    CVE-2022-0721

    Last Modified: 21 Nov 2024

    Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

    Published: 23 Feb 2022
    5.4
    Medium

    CVE-2022-0719

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.

    Published: 23 Feb 2022
    7.5
    High

    CVE-2022-0736

    Last Modified: 21 Nov 2024

    Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

    Published: 23 Feb 2022
    9.8
    Critical

    CVE-2022-25809

    Last Modified: 21 Nov 2024

    Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.

    Published: 23 Feb 2022
    9.1
    Critical

    CVE-2022-0717

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

    Published: 23 Feb 2022
    5.4
    Medium

    CVE-2022-0726

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

    Published: 23 Feb 2022
    8.8
    High

    CVE-2022-0729

    Last Modified: 21 Nov 2024

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

    Published: 23 Feb 2022
    7.5
    High

    CVE-2022-0654

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.

    Published: 22 Feb 2022
    7.5
    High

    CVE-2022-23612

    Last Modified: 22 Apr 2025

    OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize request when satisfying GET requests for `/images` & `/initfilter/scripts`. This can allow an attacker to access any file on a system running OpenMRS that is accessible to the user id OpenMRS is running under. Affected implementations should update to the latest patch version of OpenMRS Core for the minor version they use. These are: 2.1.5, 2.2.1, 2.3.5, 2.4.5 and 2.5.3. As a general rule, this vulnerability is already mitigated by Tomcat's URL normalization in Tomcat 7.0.28+. Users on older versions of Tomcat should consider upgrading their Tomcat instance as well as their OpenMRS instance.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25418

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25417

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25414

    Last Modified: 21 Nov 2024

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25083

    Last Modified: 21 Nov 2024

    TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25084

    Last Modified: 21 Nov 2024

    TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25082

    Last Modified: 21 Nov 2024

    TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25080

    Last Modified: 21 Nov 2024

    TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

    Published: 22 Feb 2022
    9.8
    Critical

    CVE-2022-25081

    Last Modified: 21 Nov 2024

    TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

    Published: 22 Feb 2022