CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2021-0099

    Last Modified: 5 May 2025

    Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 9 Feb 2022
    8.4
    High

    CVE-2021-0066

    Last Modified: 5 May 2025

    Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access.

    Published: 9 Feb 2022
    5.4
    Medium

    CVE-2022-23049

    Last Modified: 21 Nov 2024

    Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.

    Published: 9 Feb 2022
    7.2
    High

    CVE-2022-23048

    Last Modified: 21 Nov 2024

    Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.

    Published: 9 Feb 2022
    4.7
    Medium

    CVE-2021-40015

    Last Modified: 21 Nov 2024

    There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vulnerability may affect kernel stability.

    Published: 9 Feb 2022
    4.8
    Medium

    CVE-2022-23047

    Last Modified: 21 Nov 2024

    Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

    Published: 9 Feb 2022
    8.8
    High

    CVE-2021-40044

    Last Modified: 21 Nov 2024

    There is a permission verification vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may cause unauthorized operations.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2021-40045

    Last Modified: 21 Nov 2024

    There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 9 Feb 2022
    9.8
    Critical

    CVE-2021-39994

    Last Modified: 21 Nov 2024

    There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

    Published: 9 Feb 2022
    9.8
    Critical

    CVE-2021-39997

    Last Modified: 21 Nov 2024

    There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this vulnerability may cause out-of-bounds access.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2021-39992

    Last Modified: 21 Nov 2024

    There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2021-37107

    Last Modified: 21 Nov 2024

    There is an improper memory access permission configuration on ACPU.Successful exploitation of this vulnerability may cause out-of-bounds access.

    Published: 9 Feb 2022
    7.8
    High

    CVE-2021-37109

    Last Modified: 21 Nov 2024

    There is a security protection bypass vulnerability with the modem.Successful exploitation of this vulnerability may cause memory protection failure.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2021-37115

    Last Modified: 21 Nov 2024

    There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2021-39986

    Last Modified: 21 Nov 2024

    There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2021-39991

    Last Modified: 21 Nov 2024

    There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-0534

    Last Modified: 21 Nov 2024

    A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).

    Published: 9 Feb 2022
    9
    Critical

    CVE-2022-23631

    Last Modified: 24 Feb 2026

    superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the server implements at least one endpoint which uses superjson during request processing. This has been patched in superjson 1.8.1. Users are advised to update. There are no known workarounds for this issue.

    Published: 9 Feb 2022
    6.3
    Medium

    CVE-2022-23628

    Last Modified: 22 Apr 2025

    OPA is an open source, general-purpose policy engine. Under certain conditions, pretty-printing an abstract syntax tree (AST) that contains synthetic nodes could change the logic of some statements by reordering array literals. Example of policies impacted are those that parse and compare web paths. **All of these** three conditions have to be met to create an adverse effect: 1. An AST of Rego had to be **created programmatically** such that it ends up containing terms without a location (such as wildcard variables). 2. The AST had to be **pretty-printed** using the `github.com/open-policy-agent/opa/format` package. 3. The result of the pretty-printing had to be **parsed and evaluated again** via an OPA instance using the bundles, or the Golang packages. If any of these three conditions are not met, you are not affected. Notably, all three would be true if using **optimized bundles**, i.e. bundles created with `opa build -O=1` or higher. In that case, the optimizer would fulfil condition (1.), the result of that would be pretty-printed when writing the bundle to disk, fulfilling (2.). When the bundle was then used, we'd satisfy (3.). As a workaround users may disable optimization when creating bundles.

    Published: 9 Feb 2022
    7.4
    High

    CVE-2022-23622

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is a cross site scripting (XSS) vector in the `registerinline.vm` template related to the `xredirect` hidden field. This template is only used in the following conditions: 1. The wiki must be open to registration for anyone. 2. The wiki must be closed to view for Guest users or more specifically the XWiki.Registration page must be forbidden in View for guest user. A way to obtain the second condition is when administrators checked the "Prevent unregistered users from viewing pages, regardless of the page rights" box in the administration rights. This issue is patched in versions 12.10.11, 14.0-rc-1, 13.4.7, 13.10.3. There are two main ways for protecting against this vulnerability, the easiest and the best one is by applying a patch in the `registerinline.vm` template, the patch consists in checking the value of the xredirect field to ensure it matches: `<input type="hidden" name="xredirect" value="$escapetool.xml($!request.xredirect)" />`. If for some reason it's not possible to patch this file, another workaround is to ensure "Prevent unregistered users from viewing pages, regardless of the page rights" is not checked in the rights and apply a better right scheme using groups and rights on spaces.

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-23621

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through XWiki#invokeServletAndReturnAsString as `$xwiki.invokeServletAndReturnAsString("/WEB-INF/xwiki.cfg")`. This issue has been patched in XWiki versions 12.10.9, 13.4.3 and 13.7-rc-1. Users are advised to update. The only workaround is to limit SCRIPT right.

    Published: 9 Feb 2022
    6.8
    Medium

    CVE-2022-23620

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document references when serializing it on filesystem, it is possible to for the HTML export process to contain reference elements containing filesystem syntax like "../", "./". or "/" in general. The referenced elements are not properly escaped. This issue has been resolved in version 13.6-rc-1. This issue can be worked around by limiting or disabling document export.

    Published: 9 Feb 2022
    5.3
    Medium

    CVE-2022-23619

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users. This problem has been patched on XWiki 12.10.9, 13.4.1 and 13.6RC1. Users are advised yo update. There are no known workarounds for this issue.

    Published: 9 Feb 2022
    4.7
    Medium

    CVE-2022-23618

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection against URL redirection to untrusted sites, in particular some well known parameters (xredirect) can be used to perform url redirections. This problem has been patched in XWiki 12.10.7 and XWiki 13.3RC1. Users are advised to update. There are no known workarounds for this issue.

    Published: 9 Feb 2022
    6.5
    Medium

    CVE-2022-23617

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. This issue has been patched in XWiki 13.2CR1 and 12.10.6. Users are advised to update. There are no known workarounds for this issue.

    Published: 9 Feb 2022
    8.8
    High

    CVE-2022-23616

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki. The issue has been patched in XWiki 13.1RC1. There are two different possible workarounds, each consisting of modifying the XWiki/ResetPassword page. 1. The Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page. 2. The script in XWiki/ResetPassword can also be modified or removed: an administrator can replace it with a simple email contact to ask an administrator to reset the password.

    Published: 9 Feb 2022
    5.4
    Medium

    CVE-2022-23615

    Last Modified: 23 Apr 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can save a document with the right of the current user which allow accessing API requiring programming right if the current user has programming right. This has been patched in XWiki 13.0. Users are advised to update to resolve this issue. The only known workaround is to limit SCRIPT access.

    Published: 9 Feb 2022
    4.7
    Medium

    CVE-2022-22567

    Last Modified: 21 Nov 2024

    Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.

    Published: 9 Feb 2022
    6.9
    Medium

    CVE-2022-22566

    Last Modified: 21 Nov 2024

    Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.

    Published: 9 Feb 2022
    9.9
    Critical

    CVE-2021-36302

    Last Modified: 21 Nov 2024

    All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with standard level JEA credentials may potentially exploit this vulnerability to elevate privileges and take over the system.

    Published: 9 Feb 2022
    8.1
    High

    CVE-2022-21660

    Last Modified: 22 Apr 2025

    Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the `setUserInfo` function. Users are advised to update as soon as possible. There are no known workarounds.

    Published: 9 Feb 2022
    5.3
    Medium

    CVE-2021-45286

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.

    Published: 9 Feb 2022
    7.5
    High

    CVE-2021-41442

    Last Modified: 21 Nov 2024

    An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

    Published: 9 Feb 2022
    9.8
    Critical

    CVE-2021-45331

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.

    Published: 9 Feb 2022
    9.8
    Critical

    CVE-2021-45330

    Last Modified: 21 Nov 2024

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

    Published: 9 Feb 2022
    7.4
    High

    CVE-2021-41441

    Last Modified: 21 Nov 2024

    A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to visit this URL, for the router to reboot.

    Published: 9 Feb 2022
    5.3
    Medium

    CVE-2022-23280

    Last Modified: 2 Jan 2025

    Microsoft Outlook for Mac Security Feature Bypass Vulnerability

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-23276

    Last Modified: 2 Jan 2025

    SQL Server for Linux Containers Elevation of Privilege Vulnerability

    Published: 9 Feb 2022
    8.8
    High

    CVE-2022-23274

    Last Modified: 2 Jan 2025

    Microsoft Dynamics GP Remote Code Execution Vulnerability

    Published: 9 Feb 2022
    7.1
    High

    CVE-2022-23273

    Last Modified: 2 Jan 2025

    Microsoft Dynamics GP Elevation Of Privilege Vulnerability

    Published: 9 Feb 2022
    8.1
    High

    CVE-2022-23272

    Last Modified: 2 Jan 2025

    Microsoft Dynamics GP Elevation Of Privilege Vulnerability

    Published: 9 Feb 2022
    6.5
    Medium

    CVE-2022-23271

    Last Modified: 2 Jan 2025

    Microsoft Dynamics GP Elevation Of Privilege Vulnerability

    Published: 9 Feb 2022
    5.4
    Medium

    CVE-2022-23269

    Last Modified: 2 Jan 2025

    Microsoft Dynamics GP Spoofing Vulnerability

    Published: 9 Feb 2022
    8.1
    High

    CVE-2022-23256

    Last Modified: 2 Jan 2025

    Azure Data Explorer Spoofing Vulnerability

    Published: 9 Feb 2022
    5.9
    Medium

    CVE-2022-23255

    Last Modified: 2 Jan 2025

    Microsoft OneDrive for Android Security Feature Bypass Vulnerability

    Published: 9 Feb 2022
    4.9
    Medium

    CVE-2022-23254

    Last Modified: 2 Jan 2025

    Microsoft Power BI Information Disclosure Vulnerability

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-23252

    Last Modified: 2 Jan 2025

    Microsoft Office Information Disclosure Vulnerability

    Published: 9 Feb 2022
    7.8
    High

    CVE-2022-22718

    Last Modified: 30 Oct 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 9 Feb 2022
    7
    High

    CVE-2022-22717

    Last Modified: 2 Jan 2025

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 9 Feb 2022
    5.5
    Medium

    CVE-2022-22716

    Last Modified: 2 Jan 2025

    Microsoft Excel Information Disclosure Vulnerability

    Published: 9 Feb 2022