CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-0295

    Last Modified: 21 Nov 2024

    Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Feb 2022
    6.5
    Medium

    CVE-2022-0294

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Push messaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 12 Feb 2022
    8.8
    High

    CVE-2022-0293

    Last Modified: 21 Nov 2024

    Use after free in Web packaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Feb 2022
    6.5
    Medium

    CVE-2022-0292

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Fenced Frames in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

    Published: 12 Feb 2022
    6.5
    Medium

    CVE-2022-0291

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 12 Feb 2022
    9.6
    Critical

    CVE-2022-0290

    Last Modified: 21 Nov 2024

    Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 12 Feb 2022
    8.8
    High

    CVE-2022-0289

    Last Modified: 21 Nov 2024

    Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 12 Feb 2022
    5.5
    Medium

    CVE-2021-44879

    Last Modified: 21 Nov 2024

    In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.

    Published: 12 Feb 2022
    7.8
    High

    CVE-2021-45444

    Last Modified: 21 Nov 2024

    In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

    Published: 12 Feb 2022
    6.5
    Medium

    CVE-2022-0120

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.

    Published: 11 Feb 2022
    4.3
    Medium

    CVE-2022-0118

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2022-0117

    Last Modified: 21 Nov 2024

    Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 11 Feb 2022
    4.3
    Medium

    CVE-2022-0116

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0115

    Last Modified: 21 Nov 2024

    Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 11 Feb 2022
    8.1
    High

    CVE-2022-0114

    Last Modified: 21 Nov 2024

    Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2022-0113

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 11 Feb 2022
    4.3
    Medium

    CVE-2022-0112

    Last Modified: 21 Nov 2024

    Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2022-0111

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.

    Published: 11 Feb 2022
    4.3
    Medium

    CVE-2022-0110

    Last Modified: 21 Nov 2024

    Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2022-0109

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0107

    Last Modified: 21 Nov 2024

    Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0106

    Last Modified: 21 Nov 2024

    Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0105

    Last Modified: 21 Nov 2024

    Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0104

    Last Modified: 21 Nov 2024

    Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0103

    Last Modified: 21 Nov 2024

    Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0102

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0101

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0100

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0099

    Last Modified: 21 Nov 2024

    Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0098

    Last Modified: 21 Nov 2024

    Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures.

    Published: 11 Feb 2022
    9.6
    Critical

    CVE-2022-0097

    Last Modified: 21 Nov 2024

    Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-0096

    Last Modified: 21 Nov 2024

    Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2021-4102

    Last Modified: 24 Oct 2025

    Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2021-4101

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2021-4100

    Last Modified: 21 Nov 2024

    Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2021-4099

    Last Modified: 21 Nov 2024

    Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Feb 2022
    7.4
    High

    CVE-2021-4098

    Last Modified: 21 Nov 2024

    Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2021-46366

    Last Modified: 21 Nov 2024

    An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-46365

    Last Modified: 21 Nov 2024

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-46364

    Last Modified: 21 Nov 2024

    A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-46362

    Last Modified: 21 Nov 2024

    A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-46363

    Last Modified: 21 Nov 2024

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-46361

    Last Modified: 21 Nov 2024

    An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-20001

    Last Modified: 21 Nov 2024

    It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.

    Published: 11 Feb 2022
    5.9
    Medium

    CVE-2022-24968

    Last Modified: 21 Nov 2024

    In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.

    Published: 11 Feb 2022
    7
    High

    CVE-2022-22766

    Last Modified: 21 Nov 2024

    Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2020-26728

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-34235

    Last Modified: 6 Feb 2025

    Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.

    Published: 11 Feb 2022
    5.5
    Medium

    CVE-2021-39688

    Last Modified: 21 Nov 2024

    In TBD of TBD, there is a possible out of bounds read due to TBD. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-206039140References: N/A

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-39677

    Last Modified: 21 Nov 2024

    In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Product: AndroidVersions: Android-11Android ID: A-205097028

    Published: 11 Feb 2022