CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-23193

    Last Modified: 23 Apr 2025

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2021-39299

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2021-39300

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2021-39301

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2021-39297

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2021-39298

    Last Modified: 24 Feb 2026

    A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2020-6920

    Last Modified: 21 Nov 2024

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2020-6921

    Last Modified: 21 Nov 2024

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

    Published: 16 Feb 2022
    6.6
    Medium

    CVE-2022-22792

    Last Modified: 21 Nov 2024

    MobiSoft - MobiPlus User Take Over and Improper Handling of url Parameters Attacker can navigate to specific url which will expose all the users and password in clear text. http://IP/MobiPlusWeb/Handlers/MainHandler.ashx?MethodName=GridData&GridName=Users

    Published: 16 Feb 2022
    9.9
    Critical

    CVE-2022-24663

    Last Modified: 31 Jan 2025

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.

    Published: 16 Feb 2022
    9.9
    Critical

    CVE-2022-24665

    Last Modified: 31 Jan 2025

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.

    Published: 16 Feb 2022
    7.2
    High

    CVE-2021-4134

    Last Modified: 31 Jan 2025

    The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 4.7.4.

    Published: 16 Feb 2022
    9.9
    Critical

    CVE-2022-24664

    Last Modified: 31 Jan 2025

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-0513

    Last Modified: 10 Feb 2025

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2021-4106

    Last Modified: 21 Nov 2024

    A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0

    Published: 16 Feb 2022
    7.8
    High

    CVE-2020-6922

    Last Modified: 21 Nov 2024

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2020-6917

    Last Modified: 21 Nov 2024

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2020-6919

    Last Modified: 21 Nov 2024

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2020-6918

    Last Modified: 21 Nov 2024

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

    Published: 16 Feb 2022
    7.5
    High

    CVE-2021-22050

    Last Modified: 21 Nov 2024

    ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.

    Published: 16 Feb 2022
    7.5
    High

    CVE-2021-22043

    Last Modified: 21 Nov 2024

    VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2021-22042

    Last Modified: 21 Nov 2024

    VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.

    Published: 16 Feb 2022
    6.7
    Medium

    CVE-2021-22041

    Last Modified: 21 Nov 2024

    VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

    Published: 16 Feb 2022
    6.7
    Medium

    CVE-2021-22040

    Last Modified: 21 Nov 2024

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2021-26726

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.

    Published: 16 Feb 2022
    7.5
    High

    CVE-2021-45391

    Last Modified: 21 Nov 2024

    A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-23358

    Last Modified: 21 Nov 2024

    EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2022-1043

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges.

    Published: 16 Feb 2022
    —
    Unknown

    CVE-2021-46388

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: Reason: The issue is not a vulnerability (fails CNT2) - Has no impact on availability, integrity or confidence as only documented html templates are shown without additional data or the option to store changes. Notes

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-0559

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

    Published: 16 Feb 2022
    5.5
    Medium

    CVE-2022-0614

    Last Modified: 21 Nov 2024

    Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.

    Published: 16 Feb 2022
    5.4
    Medium

    CVE-2022-0612

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

    Published: 16 Feb 2022
    8.8
    High

    CVE-2022-25241

    Last Modified: 21 Nov 2024

    In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).

    Published: 16 Feb 2022
    8.8
    High

    CVE-2022-25242

    Last Modified: 21 Nov 2024

    In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-25235

    Last Modified: 5 May 2025

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2022-25236

    Last Modified: 5 May 2025

    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

    Published: 16 Feb 2022
    9.1
    Critical

    CVE-2021-43302

    Last Modified: 4 Nov 2025

    Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when the filename is shorter than 4 characters.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2021-43301

    Last Modified: 4 Nov 2025

    Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2021-43299

    Last Modified: 4 Nov 2025

    Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

    Published: 16 Feb 2022
    7.5
    High

    CVE-2022-25271

    Last Modified: 21 Nov 2024

    Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-25255

    Last Modified: 21 Nov 2024

    In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2021-43303

    Last Modified: 4 Nov 2025

    Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied

    Published: 16 Feb 2022
    6.5
    Medium

    CVE-2022-0613

    Last Modified: 21 Nov 2024

    Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-0646

    Last Modified: 21 Nov 2024

    A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system or escalate their privileges on the system. It is actual from Linux Kernel 5.17-rc1 (when mctp-serial.c introduced) till 5.17-rc5.

    Published: 16 Feb 2022
    4.6
    Medium

    CVE-2022-25258

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

    Published: 16 Feb 2022
    7.8
    High

    CVE-2022-25265

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.

    Published: 16 Feb 2022
    9.8
    Critical

    CVE-2021-43300

    Last Modified: 4 Nov 2025

    Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

    Published: 16 Feb 2022
    6.3
    Medium

    CVE-2022-0611

    Last Modified: 24 Feb 2026

    Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.

    Published: 15 Feb 2022
    6.5
    Medium

    CVE-2021-46252

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses.

    Published: 15 Feb 2022
    6.1
    Medium

    CVE-2021-46251

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

    Published: 15 Feb 2022