CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-0629

    Last Modified: 21 Nov 2024

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 17 Feb 2022
    8.2
    High

    CVE-2021-21708

    Last Modified: 21 Nov 2024

    In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

    Published: 17 Feb 2022
    8.8
    High

    CVE-2022-0566

    Last Modified: 16 Apr 2025

    It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message. This vulnerability affects Thunderbird < 91.6.1.

    Published: 17 Feb 2022
    8.8
    High

    CVE-2022-22620

    Last Modified: 23 Oct 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

    Published: 17 Feb 2022
    8.8
    High

    CVE-2022-28042

    Last Modified: 21 Nov 2024

    stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

    Published: 17 Feb 2022
    8.8
    High

    CVE-2022-28048

    Last Modified: 21 Nov 2024

    STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.

    Published: 17 Feb 2022
    7.8
    High

    CVE-2021-44731

    Last Modified: 21 Nov 2024

    A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

    Published: 17 Feb 2022
    6.5
    Medium

    CVE-2022-28041

    Last Modified: 21 Nov 2024

    stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

    Published: 17 Feb 2022
    6.5
    Medium

    CVE-2022-25270

    Last Modified: 21 Nov 2024

    The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

    Published: 16 Feb 2022
    5.1
    Medium

    CVE-2022-23636

    Last Modified: 23 Apr 2025

    Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in the pooling instance allocator in Wasmtime's runtime where a failure to instantiate an instance for a module that defines an `externref` global will result in an invalid drop of a `VMExternRef` via an uninitialized pointer. A number of conditions listed in the GitHub Security Advisory must be true in order for an instance to be vulnerable to this issue. Maintainers believe that the effective impact of this bug is relatively small because the usage of `externref` is still uncommon and without a resource limiter configured on the `Store`, which is not the default configuration, it is only possible to trigger the bug from an error returned by `mprotect` or `VirtualAlloc`. Note that on Linux with the `uffd` feature enabled, it is only possible to trigger the bug from a resource limiter as the call to `mprotect` is skipped. The bug has been fixed in 0.34.1 and 0.33.1 and users are encouraged to upgrade as soon as possible. If it is not possible to upgrade to version 0.34.1 or 0.33.1 of the `wasmtime` crate, it is recommend that support for the reference types proposal be disabled by passing `false` to `Config::wasm_reference_types`. Doing so will prevent modules that use `externref` from being loaded entirely.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-22885

    Last Modified: 21 Nov 2024

    Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-22881

    Last Modified: 21 Nov 2024

    Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-22880

    Last Modified: 21 Nov 2024

    Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2022-24985

    Last Modified: 21 Nov 2024

    Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms on their server.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-24984

    Last Modified: 21 Nov 2024

    Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all executable content (e.g., .phtml or .php.bak) is blocked.

    Published: 16 Feb 2022
    7.5
    High

    CVE-2022-24983

    Last Modified: 21 Nov 2024

    Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs because the Unique ID field is contained in the POST response upon submitting a form.

    Published: 16 Feb 2022
    6.5
    Medium

    CVE-2022-24982

    Last Modified: 21 Nov 2024

    Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form users. admin.php contains a hidden base64-encoded string with these credentials.

    Published: 16 Feb 2022
    6.1
    Medium

    CVE-2022-24981

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to admin.php.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2021-3242

    Last Modified: 21 Nov 2024

    DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2021-3578

    Last Modified: 21 Nov 2024

    A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2022-23644

    Last Modified: 23 Apr 2025

    BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a logged-in user. The problem has been patched and administrators should upgrade to version 0.3.0 As a workaround, BookWyrm instances can close registration and limit members to trusted individuals.

    Published: 16 Feb 2022
    5.4
    Medium

    CVE-2022-22853

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Name field.

    Published: 16 Feb 2022
    7.3
    High

    CVE-2021-23682

    Last Modified: 21 Nov 2024

    This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.

    Published: 16 Feb 2022
    2.4
    Low

    CVE-2019-4352

    Last Modified: 21 Nov 2024

    IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494.

    Published: 16 Feb 2022
    4.6
    Medium

    CVE-2019-4351

    Last Modified: 21 Nov 2024

    IBM Maximo Anywhere 7.6.4.0 applications could disclose sensitive information to a user with physical access to the device. IBM X-Force ID: 161493.

    Published: 16 Feb 2022
    6.5
    Medium

    CVE-2019-4291

    Last Modified: 21 Nov 2024

    IBM Maximo Anywhere 7.6.4.0 could allow an attacker to reverse engineer the application due to the lack of binary protection precautions. IBM X-Force ID: 160697.

    Published: 16 Feb 2022
    4.4
    Medium

    CVE-2022-0494

    Last Modified: 21 Nov 2024

    A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues with confidentiality.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-22945

    Last Modified: 21 Nov 2024

    VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.

    Published: 16 Feb 2022
    —
    Unknown

    CVE-2021-4220

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-23804

    Last Modified: 15 Apr 2025

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-23803

    Last Modified: 15 Apr 2025

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 16 Feb 2022
    5.3
    Medium

    CVE-2021-21966

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2021-21958

    Last Modified: 15 Apr 2025

    A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory corruption and potential arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 16 Feb 2022
    7
    High

    CVE-2022-23202

    Last Modified: 23 Apr 2025

    Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The attacker has to deliver the DLL on the same folder as the installer which makes it as a high complexity attack vector.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-24086

    Last Modified: 23 Oct 2025

    Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-23200

    Last Modified: 23 Apr 2025

    Adobe After Effects versions 22.1.1 (and earlier) and 18.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23204

    Last Modified: 23 Apr 2025

    Adobe Premiere Rush versions 2.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-23203

    Last Modified: 23 Apr 2025

    Adobe Photoshop versions 22.5.4 (and earlier) and 23.1 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Photoshop.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23197

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23199

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23198

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23196

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23195

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23194

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23190

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23191

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-23186

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23189

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-23188

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted malicious file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted malicious file in Illustrator.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-23192

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022