CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2022-25315

    Last Modified: 5 May 2025

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

    Published: 18 Feb 2022
    6.5
    Medium

    CVE-2022-25313

    Last Modified: 30 May 2025

    In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

    Published: 18 Feb 2022
    5.4
    Medium

    CVE-2021-46108

    Last Modified: 21 Nov 2024

    D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.

    Published: 18 Feb 2022
    9.8
    Critical

    CVE-2022-22922

    Last Modified: 21 Nov 2024

    TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.

    Published: 18 Feb 2022
    5.9
    Medium

    CVE-2021-45081

    Last Modified: 21 Nov 2024

    An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more secure HTTPS.

    Published: 18 Feb 2022
    6.2
    Medium

    CVE-2022-23645

    Last Modified: 23 Apr 2025

    swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.

    Published: 18 Feb 2022
    4.3
    Medium

    CVE-2022-25318

    Last Modified: 21 Nov 2024

    An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.

    Published: 18 Feb 2022
    5.3
    Medium

    CVE-2022-25319

    Last Modified: 21 Nov 2024

    An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.

    Published: 18 Feb 2022
    5.3
    Medium

    CVE-2022-25320

    Last Modified: 21 Nov 2024

    An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.

    Published: 18 Feb 2022
    7.8
    High

    CVE-2021-45082

    Last Modified: 21 Nov 2024

    An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

    Published: 18 Feb 2022
    7.1
    High

    CVE-2021-45083

    Last Modified: 21 Nov 2024

    An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.

    Published: 18 Feb 2022
    7.5
    High

    CVE-2022-23647

    Last Modified: 23 Apr 2025

    Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.

    Published: 18 Feb 2022
    7.8
    High

    CVE-2022-24050

    Last Modified: 21 Nov 2024

    MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

    Published: 18 Feb 2022
    7.8
    High

    CVE-2022-24051

    Last Modified: 21 Nov 2024

    MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

    Published: 18 Feb 2022
    6.1
    Medium

    CVE-2022-25317

    Last Modified: 21 Nov 2024

    An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.

    Published: 18 Feb 2022
    7.8
    High

    CVE-2022-24048

    Last Modified: 21 Nov 2024

    MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16191.

    Published: 18 Feb 2022
    7.8
    High

    CVE-2022-24052

    Last Modified: 21 Nov 2024

    MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16190.

    Published: 18 Feb 2022
    6.1
    Medium

    CVE-2022-25321

    Last Modified: 21 Nov 2024

    An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.

    Published: 18 Feb 2022
    8.8
    High

    CVE-2021-41599

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.3 and was fixed in versions 3.0.21, 3.1.13, 3.2.5. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 17 Feb 2022
    8.2
    High

    CVE-2021-4120

    Last Modified: 21 Nov 2024

    snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

    Published: 17 Feb 2022
    7.8
    High

    CVE-2021-44730

    Last Modified: 21 Nov 2024

    snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

    Published: 17 Feb 2022
    3.8
    Low

    CVE-2021-3155

    Last Modified: 21 Nov 2024

    snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

    Published: 17 Feb 2022
    9.8
    Critical

    CVE-2021-46319

    Last Modified: 21 Nov 2024

    Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users can use this vulnerability to use "\ " or backticks to bypass the shell metacharacters in the ssid0 or ssid1 parameters to execute arbitrary commands.This vulnerability is due to the fact that CVE-2019-17509 is not fully patched and can be bypassed by using line breaks or backticks on its basis.

    Published: 17 Feb 2022
    9.8
    Critical

    CVE-2021-46315

    Last Modified: 21 Nov 2024

    Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicoius users can use this vulnerability to use "\ " or backticks in the shell metacharacters in the ssid0 or ssid1 parameters to cause arbitrary command execution. Since CVE-2019-17510 vulnerability has not been patched and improved www/hnap1/control/setwizardconfig.php, can also use line breaks and backquotes to bypass.

    Published: 17 Feb 2022
    9.8
    Critical

    CVE-2022-22916

    Last Modified: 21 Nov 2024

    O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

    Published: 17 Feb 2022
    9.8
    Critical

    CVE-2021-46314

    Last Modified: 21 Nov 2024

    A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable domain name.

    Published: 17 Feb 2022
    7.5
    High

    CVE-2022-22914

    Last Modified: 21 Nov 2024

    An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal.

    Published: 17 Feb 2022
    5.9
    Medium

    CVE-2022-23646

    Last Modified: 23 Apr 2025

    Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentation of Critical Information. In order to be affected, the `next.config.js` file must have an `images.domains` array assigned and the image host assigned in `images.domains` must allow user-provided SVG. If the `next.config.js` file has `images.loader` assigned to something other than default, the instance is not affected. Version 12.1.0 contains a patch for this issue. As a workaround, change `next.config.js` to use a different `loader configuration` other than the default.

    Published: 17 Feb 2022
    9.8
    Critical

    CVE-2021-45382

    Last Modified: 10 Nov 2025

    A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.

    Published: 17 Feb 2022
    6.1
    Medium

    CVE-2014-8597

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.

    Published: 17 Feb 2022
    9.8
    Critical

    CVE-2022-22912

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.

    Published: 17 Feb 2022
    6.5
    Medium

    CVE-2022-0633

    Last Modified: 21 Nov 2024

    The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

    Published: 17 Feb 2022
    7.5
    High

    CVE-2021-46247

    Last Modified: 21 Nov 2024

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

    Published: 17 Feb 2022
    7.5
    High

    CVE-2022-24683

    Last Modified: 21 Nov 2024

    HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

    Published: 17 Feb 2022
    4.3
    Medium

    CVE-2022-0638

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

    Published: 17 Feb 2022
    7.5
    High

    CVE-2021-39034

    Last Modified: 21 Nov 2024

    IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.

    Published: 17 Feb 2022
    9.8
    Critical

    CVE-2021-44868

    Last Modified: 21 Nov 2024

    A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do

    Published: 17 Feb 2022
    7.5
    High

    CVE-2022-20653

    Last Modified: 21 Nov 2024

    A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in DNS name resolution by the affected software. An attacker could exploit this vulnerability by sending specially formatted email messages that are processed by an affected device. A successful exploit could allow the attacker to cause the device to become unreachable from management interfaces or to process additional email messages for a period of time until the device recovers, resulting in a DoS condition. Continued attacks could cause the device to become completely unavailable, resulting in a persistent DoS condition.

    Published: 17 Feb 2022
    5.3
    Medium

    CVE-2022-20750

    Last Modified: 21 Nov 2024

    A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software could allow an unauthenticated, remote attacker to cause the checkpoint manager process to restart upon receipt of malformed TCP data. This vulnerability is due to improper input validation of an ingress TCP packet. An attacker could exploit this vulnerability by sending crafted TCP data to the affected application. A successful exploit could allow the attacker to cause a denial of service (DoS) condition due to the checkpoint manager process restarting.

    Published: 17 Feb 2022
    6.1
    Medium

    CVE-2022-20659

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 17 Feb 2022
    7.4
    High

    CVE-2022-23632

    Last Modified: 23 Apr 2025

    Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a wrong TLS configuration. When sending a request using FQDN handled by a router configured with a dedicated TLS configuration, the TLS configuration falls back to the default configuration that might not correspond to the configured one. If the CNAME flattening is enabled, the selected TLS configuration is the SNI one and the routing uses the CNAME value, so this can skip the expected TLS configuration. Version 2.6.1 contains a patch for this issue. As a workaround, one may add the FDQN to the host rule. However, there is no workaround if the CNAME flattening is enabled.

    Published: 17 Feb 2022
    5.5
    Medium

    CVE-2022-23319

    Last Modified: 21 Nov 2024

    A segmentation fault during PCF file parsing in pcf2bdf versions >=1.05 allows an attacker to trigger a program crash via a specially crafted PCF font file. This crash affects the availability of the software and dependent downstream components.

    Published: 17 Feb 2022
    5.5
    Medium

    CVE-2022-22899

    Last Modified: 21 Nov 2024

    Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.

    Published: 17 Feb 2022
    7.1
    High

    CVE-2022-23318

    Last Modified: 21 Nov 2024

    A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially crafted PCF font file. This out-of-bound read may lead to an application crash, information disclosure via program memory or other context-dependent impact.

    Published: 17 Feb 2022
    7.8
    High

    CVE-2021-46368

    Last Modified: 21 Nov 2024

    TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

    Published: 17 Feb 2022
    9.1
    Critical

    CVE-2022-0623

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

    Published: 17 Feb 2022
    5.3
    Medium

    CVE-2022-24953

    Last Modified: 21 Nov 2024

    The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.

    Published: 17 Feb 2022
    5.5
    Medium

    CVE-2022-22901

    Last Modified: 21 Nov 2024

    There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.

    Published: 17 Feb 2022
    5.3
    Medium

    CVE-2022-0622

    Last Modified: 21 Nov 2024

    Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.

    Published: 17 Feb 2022
    5.3
    Medium

    CVE-2022-0639

    Last Modified: 16 Dec 2025

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

    Published: 17 Feb 2022