CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2022-20710

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 10 Feb 2022
    10
    Critical

    CVE-2022-20711

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 10 Feb 2022
    10
    Critical

    CVE-2022-20712

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 10 Feb 2022
    5.8
    Medium

    CVE-2022-20738

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypass the file inspection feature. This vulnerability is due to insufficient restrictions in the file inspection feature. An attacker could exploit this vulnerability by downloading a crafted payload through specific methods. A successful exploit could allow the attacker to bypass file inspection protections and download a malicious payload.

    Published: 10 Feb 2022
    10
    Critical

    CVE-2022-20749

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 10 Feb 2022
    6.1
    Medium

    CVE-2021-41445

    Last Modified: 21 Nov 2024

    A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.

    Published: 10 Feb 2022
    6.1
    Medium

    CVE-2021-31814

    Last Modified: 21 Nov 2024

    In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.

    Published: 10 Feb 2022
    6.5
    Medium

    CVE-2021-37613

    Last Modified: 21 Nov 2024

    Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.

    Published: 10 Feb 2022
    5.8
    Medium

    CVE-2021-3398

    Last Modified: 21 Nov 2024

    Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.

    Published: 10 Feb 2022
    8.8
    High

    CVE-2021-44892

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.

    Published: 10 Feb 2022
    5.3
    Medium

    CVE-2022-24111

    Last Modified: 21 Nov 2024

    In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.

    Published: 10 Feb 2022
    8.8
    High

    CVE-2022-0435

    Last Modified: 21 Nov 2024

    A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.

    Published: 10 Feb 2022
    5.3
    Medium

    CVE-2021-45901

    Last Modified: 21 Nov 2024

    The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

    Published: 10 Feb 2022
    9.8
    Critical

    CVE-2021-25992

    Last Modified: 21 Nov 2024

    In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.

    Published: 10 Feb 2022
    5.4
    Medium

    CVE-2022-0558

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

    Published: 10 Feb 2022
    6.3
    Medium

    CVE-2022-0586

    Last Modified: 3 Nov 2025

    Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

    Published: 10 Feb 2022
    4.3
    Medium

    CVE-2022-0585

    Last Modified: 3 Nov 2025

    Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file

    Published: 10 Feb 2022
    6.3
    Medium

    CVE-2022-0581

    Last Modified: 3 Nov 2025

    Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

    Published: 10 Feb 2022
    —
    Unknown

    CVE-2022-24941

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Feb 2022
    —
    Unknown

    CVE-2022-24940

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Feb 2022
    —
    Unknown

    CVE-2022-24943

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Feb 2022
    —
    Unknown

    CVE-2022-24944

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Feb 2022
    —
    Unknown

    CVE-2022-24945

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 10 Feb 2022
    6.3
    Medium

    CVE-2022-0583

    Last Modified: 3 Nov 2025

    Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

    Published: 10 Feb 2022
    6.3
    Medium

    CVE-2022-0582

    Last Modified: 3 Nov 2025

    Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

    Published: 10 Feb 2022
    8.8
    High

    CVE-2021-22954

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.

    Published: 9 Feb 2022
    —
    Unknown

    CVE-2021-40696

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-21825

    Last Modified: 21 Nov 2024

    An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2021-26616

    Last Modified: 21 Nov 2024

    An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-20046

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS06142410.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20045

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID: ALPS06126820.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20044

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID: ALPS06126814.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20043

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06148177; Issue ID: ALPS06148177.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20041

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108596; Issue ID: ALPS06108596.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-20042

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108487; Issue ID: ALPS06108487.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20040

    Last Modified: 21 Nov 2024

    In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219150; Issue ID: ALPS06219150.

    Published: 9 Feb 2022
    6.7
    Medium

    CVE-2022-20039

    Last Modified: 21 Nov 2024

    In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183345; Issue ID: ALPS06183345.

    Published: 9 Feb 2022
    6.7
    Medium

    CVE-2022-20038

    Last Modified: 21 Nov 2024

    In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Issue ID: ALPS06183335.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-20036

    Last Modified: 21 Nov 2024

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID: ALPS06171689.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-20037

    Last Modified: 21 Nov 2024

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID: ALPS06171705.

    Published: 9 Feb 2022
    4.4
    Medium

    CVE-2022-20035

    Last Modified: 21 Nov 2024

    In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ID: ALPS06171675.

    Published: 9 Feb 2022
    6.8
    Medium

    CVE-2022-20034

    Last Modified: 21 Nov 2024

    In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-20017

    Last Modified: 21 Nov 2024

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862991; Issue ID: ALPS05862991.

    Published: 9 Feb 2022
    4.4
    Medium

    CVE-2022-20033

    Last Modified: 21 Nov 2024

    In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973; Issue ID: ALPS05862973.

    Published: 9 Feb 2022
    4.1
    Medium

    CVE-2022-20032

    Last Modified: 21 Nov 2024

    In vow driver, there is a possible memory corruption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05852822; Issue ID: ALPS05852822.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20031

    Last Modified: 21 Nov 2024

    In fb driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05850708; Issue ID: ALPS05850708.

    Published: 9 Feb 2022
    4.4
    Medium

    CVE-2022-20029

    Last Modified: 21 Nov 2024

    In cmdq driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05747150; Issue ID: ALPS05747150.

    Published: 9 Feb 2022
    6.7
    Medium

    CVE-2022-20030

    Last Modified: 21 Nov 2024

    In vow driver, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05837793; Issue ID: ALPS05837793.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20028

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198663; Issue ID: ALPS06198663.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-20026

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126827; Issue ID: ALPS06126827.

    Published: 9 Feb 2022