CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2022-23995

    Last Modified: 21 Nov 2024

    Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

    Published: 11 Feb 2022
    3.3
    Low

    CVE-2022-23994

    Last Modified: 21 Nov 2024

    An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

    Published: 11 Feb 2022
    4.4
    Medium

    CVE-2022-23434

    Last Modified: 21 Nov 2024

    A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.

    Published: 11 Feb 2022
    4.3
    Medium

    CVE-2022-23433

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.

    Published: 11 Feb 2022
    6.4
    Medium

    CVE-2022-23431

    Last Modified: 21 Nov 2024

    An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

    Published: 11 Feb 2022
    6.4
    Medium

    CVE-2022-23432

    Last Modified: 21 Nov 2024

    An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

    Published: 11 Feb 2022
    5.3
    Medium

    CVE-2022-23429

    Last Modified: 21 Nov 2024

    An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.

    Published: 11 Feb 2022
    8.4
    High

    CVE-2022-23428

    Last Modified: 21 Nov 2024

    An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

    Published: 11 Feb 2022
    3.9
    Low

    CVE-2022-23427

    Last Modified: 21 Nov 2024

    PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.

    Published: 11 Feb 2022
    8.6
    High

    CVE-2022-23425

    Last Modified: 21 Nov 2024

    Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.

    Published: 11 Feb 2022
    4.4
    Medium

    CVE-2022-23426

    Last Modified: 21 Nov 2024

    A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

    Published: 11 Feb 2022
    7.1
    High

    CVE-2022-22292

    Last Modified: 21 Nov 2024

    Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

    Published: 11 Feb 2022
    5.5
    Medium

    CVE-2022-22291

    Last Modified: 21 Nov 2024

    Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.

    Published: 11 Feb 2022
    5.4
    Medium

    CVE-2021-4046

    Last Modified: 21 Nov 2024

    The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.

    Published: 11 Feb 2022
    3.5
    Low

    CVE-2021-4035

    Last Modified: 21 Nov 2024

    A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2021-31932

    Last Modified: 21 Nov 2024

    Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.

    Published: 11 Feb 2022
    4.4
    Medium

    CVE-2021-44111

    Last Modified: 21 Nov 2024

    A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-23597

    Last Modified: 21 Nov 2024

    This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **Note:** This is a bypass of CVE-2020-8136 (https://security.snyk.io/vuln/SNYK-JS-FASTIFYMULTIPART-1290382).

    Published: 11 Feb 2022
    7.5
    High

    CVE-2020-13677

    Last Modified: 21 Nov 2024

    Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.

    Published: 11 Feb 2022
    9.9
    Critical

    CVE-2021-42940

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2020-13676

    Last Modified: 21 Nov 2024

    The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed.

    Published: 11 Feb 2022
    7.5
    High

    CVE-2020-13670

    Last Modified: 21 Nov 2024

    Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2020-13674

    Last Modified: 21 Nov 2024

    The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2020-13675

    Last Modified: 21 Nov 2024

    Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by modules on the site.

    Published: 11 Feb 2022
    6.1
    Medium

    CVE-2020-13673

    Last Modified: 21 Nov 2024

    The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.

    Published: 11 Feb 2022
    6.1
    Medium

    CVE-2020-13672

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x versions prior to 9.0.12; 8.9.x versions prior to 8.9.14; 7.x versions prior to 7.80.

    Published: 11 Feb 2022
    6.1
    Medium

    CVE-2020-13669

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2021-45385

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without assign memory buffer to `pb->pdata` and did not exit the program. So the program crashes when it tries to access the pb->data, in jfif_encode() at jfif.c:763. This is due to the incomplete patch for CVE-2020-13438.

    Published: 11 Feb 2022
    6.1
    Medium

    CVE-2020-13668

    Last Modified: 21 Nov 2024

    Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2020-36062

    Last Modified: 21 Nov 2024

    Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

    Published: 11 Feb 2022
    6.5
    Medium

    CVE-2021-38679

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.22 and later

    Published: 11 Feb 2022
    6.1
    Medium

    CVE-2022-0560

    Last Modified: 21 Nov 2024

    Open Redirect in Packagist microweber/microweber prior to 1.2.11.

    Published: 11 Feb 2022
    8.8
    High

    CVE-2022-24289

    Last Modified: 21 Nov 2024

    Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) feature is a web services-based technology that provides object persistence and query functionality to 'remote' applications. In Apache Cayenne 4.1 and earlier, running on non-current patch versions of Java, an attacker with client access to Cayenne ROP can transmit a malicious payload to any vulnerable third-party dependency on the server. This can result in arbitrary code execution.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2022-24112

    Last Modified: 23 Oct 2025

    An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

    Published: 11 Feb 2022
    8.4
    High

    CVE-2021-35077

    Last Modified: 21 Nov 2024

    Possible use after free scenario in compute offloads to DSP while multiple calls spawn a dynamic process in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 11 Feb 2022
    8.4
    High

    CVE-2021-35075

    Last Modified: 21 Nov 2024

    Possible null pointer dereference due to lack of WDOG structure validation during registration in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 11 Feb 2022
    8.4
    High

    CVE-2021-35074

    Last Modified: 21 Nov 2024

    Possible integer overflow due to improper fragment datatype while calculating number of fragments in a request message in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-35069

    Last Modified: 21 Nov 2024

    Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 11 Feb 2022
    8.4
    High

    CVE-2021-35068

    Last Modified: 21 Nov 2024

    Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer dereference in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 11 Feb 2022
    7.5
    High

    CVE-2021-30326

    Last Modified: 21 Nov 2024

    Possible assertion due to improper size validation while processing the DownlinkPreemption IE in an RRC Reconfiguration/RRC Setup message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 11 Feb 2022
    6.7
    Medium

    CVE-2021-30325

    Last Modified: 21 Nov 2024

    Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 11 Feb 2022
    6.7
    Medium

    CVE-2021-30324

    Last Modified: 21 Nov 2024

    Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-30323

    Last Modified: 21 Nov 2024

    Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-30322

    Last Modified: 21 Nov 2024

    Possible out of bounds write due to improper validation of number of GPIOs configured in an internal parameters array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 11 Feb 2022
    8.4
    High

    CVE-2021-30318

    Last Modified: 21 Nov 2024

    Improper validation of input when provisioning the HDCP key can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 11 Feb 2022
    9.3
    Critical

    CVE-2021-30317

    Last Modified: 21 Nov 2024

    Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 11 Feb 2022
    7.8
    High

    CVE-2021-30309

    Last Modified: 21 Nov 2024

    Improper size validation of QXDM commands can lead to memory corruption in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 11 Feb 2022
    7.2
    High

    CVE-2022-0557

    Last Modified: 21 Nov 2024

    OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

    Published: 11 Feb 2022
    4.7
    Medium

    CVE-2023-1582

    Last Modified: 13 Feb 2025

    A race problem was found in fs/proc/task_mmu.c in the memory management sub-component in the Linux kernel. This issue may allow a local attacker with user privilege to cause a denial of service.

    Published: 11 Feb 2022
    9.8
    Critical

    CVE-2022-24961

    Last Modified: 21 Nov 2024

    In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

    Published: 11 Feb 2022