CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-22808

    Last Modified: 21 Nov 2024

    A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)

    Published: 9 Feb 2022
    8.8
    High

    CVE-2022-24676

    Last Modified: 21 Nov 2024

    update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.

    Published: 8 Feb 2022
    9.8
    Critical

    CVE-2022-24677

    Last Modified: 21 Nov 2024

    Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

    Published: 8 Feb 2022
    5
    Medium

    CVE-2022-23627

    Last Modified: 23 Apr 2025

    ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like command sent to bot `A` targeting bot `B` has incorrectly verified user's access against bot `A` - instead of bot `B`, to which the command was originally designated. This in result allowed access to resources beyond those configured, being a security threat affecting confidentiality of other bot instances. A successful attack exploiting this bug requires a significant access granted explicitly by original owner of the ASF process prior to that, as attacker has to control at least a single bot in the process to make use of this inadequate access verification loophole. The issue is patched in ASF V5.2.2.5, V5.2.3.2 and future versions. Users are advised to update as soon as possible.

    Published: 8 Feb 2022
    5.4
    Medium

    CVE-2021-45919

    Last Modified: 21 Nov 2024

    Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.

    Published: 8 Feb 2022
    6.1
    Medium

    CVE-2021-45329

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.

    Published: 8 Feb 2022
    7.5
    High

    CVE-2022-0524

    Last Modified: 21 Nov 2024

    Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

    Published: 8 Feb 2022
    8.5
    High

    CVE-2022-23626

    Last Modified: 22 Apr 2025

    m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Published: 8 Feb 2022
    7.1
    High

    CVE-2022-0522

    Last Modified: 21 Nov 2024

    Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

    Published: 8 Feb 2022
    7.1
    High

    CVE-2022-0521

    Last Modified: 21 Nov 2024

    Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.

    Published: 8 Feb 2022
    7.8
    High

    CVE-2022-0520

    Last Modified: 21 Nov 2024

    Use After Free in NPM radare2.js prior to 5.6.2.

    Published: 8 Feb 2022
    7.1
    High

    CVE-2022-0519

    Last Modified: 21 Nov 2024

    Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.

    Published: 8 Feb 2022
    7.1
    High

    CVE-2022-0518

    Last Modified: 21 Nov 2024

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.

    Published: 8 Feb 2022
    9.8
    Critical

    CVE-2022-0139

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

    Published: 8 Feb 2022
    7.5
    High

    CVE-2022-21986

    Last Modified: 2 Jan 2025

    .NET Denial of Service Vulnerability

    Published: 8 Feb 2022
    6.1
    Medium

    CVE-2021-45328

    Last Modified: 21 Nov 2024

    Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

    Published: 8 Feb 2022
    9.8
    Critical

    CVE-2021-45327

    Last Modified: 21 Nov 2024

    Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.

    Published: 8 Feb 2022
    8.8
    High

    CVE-2021-45326

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.

    Published: 8 Feb 2022
    7.5
    High

    CVE-2021-45325

    Last Modified: 21 Nov 2024

    Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.

    Published: 8 Feb 2022
    6.5
    Medium

    CVE-2021-44864

    Last Modified: 21 Nov 2024

    TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash router httpd services via /userRpm/PingIframeRpm.htm request which contains redundant & in parameter.

    Published: 8 Feb 2022
    5.4
    Medium

    CVE-2022-0510

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.

    Published: 8 Feb 2022
    6.5
    Medium

    CVE-2021-44956

    Last Modified: 21 Nov 2024

    Two Heap based buffer overflow vulnerabilities exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23852. Issues that are in the jfif_decode function at ffjpeg/src/jfif.c (line 552) could cause a Denial of Service by using a crafted jpeg file.

    Published: 8 Feb 2022
    6.5
    Medium

    CVE-2021-44957

    Last Modified: 21 Nov 2024

    Global buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in the jfif_encode function at ffjpeg/src/jfif.c (line 708) could cause a Denial of Service by using a crafted jpeg file.

    Published: 8 Feb 2022
    9.8
    Critical

    CVE-2022-23340

    Last Modified: 21 Nov 2024

    Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.

    Published: 8 Feb 2022
    8.8
    High

    CVE-2022-23331

    Last Modified: 21 Nov 2024

    In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.

    Published: 8 Feb 2022
    5.4
    Medium

    CVE-2022-0509

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.

    Published: 8 Feb 2022
    5.3
    Medium

    CVE-2022-0508

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9d6832

    Published: 8 Feb 2022
    6.1
    Medium

    CVE-2022-22146

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 8 Feb 2022
    6.1
    Medium

    CVE-2022-22142

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in the checkbox of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 8 Feb 2022
    6.1
    Medium

    CVE-2022-21805

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in the attached file name of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.

    Published: 8 Feb 2022
    5.2
    Medium

    CVE-2022-21799

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier allows an attacker on the adjacent network to inject an arbitrary script via unspecified vectors.

    Published: 8 Feb 2022
    9.6
    Critical

    CVE-2022-21241

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.

    Published: 8 Feb 2022
    7.5
    High

    CVE-2022-21193

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an arbitrary file on the server via unspecified vectors.

    Published: 8 Feb 2022
    8.8
    High

    CVE-2022-21173

    Last Modified: 21 Nov 2024

    Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v1.05 and earlier, WRH-300LB3-S firmware v1.05 and earlier, WRH-300PN3-S firmware v1.05 and earlier, WRH-300WH3-S firmware v1.05 and earlier, and WRH-300YG3-S firmware v1.05 and earlier) allows an attacker on the adjacent network to execute an arbitrary OS command via unspecified vectors.

    Published: 8 Feb 2022
    4.8
    Medium

    CVE-2021-20877

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS MF Series (MF113W/MF212W/MF217W/MF227DW/MF229DW, MF232W/MF244DW/MF247DW/MF249DW, MF264DW/MF267DW/MF269DW/MF269DW VP, and MF4570DN/MF4570DW/MF4770N/MF4880DW/MF4890DW) and imageCLASS LBP Series (LBP113W/LBP151DW/LBP162DW ) sold in the US, and iSENSYS (LBP162DW, LBP113W, LBP151DW, MF269dw, MF267dw, MF264dw, MF113w, MF249dw, MF247dw, MF244dw, MF237w, MF232w, MF229dw, MF217w, MF212w, MF4780w, and MF4890dw) and imageRUNNER (2206IF, 2204N, and 2204F) sold in Europe) allows remote attackers to inject an arbitrary script via unspecified vectors.

    Published: 8 Feb 2022
    6.5
    Medium

    CVE-2022-0504

    Last Modified: 21 Nov 2024

    Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

    Published: 8 Feb 2022
    6.5
    Medium

    CVE-2022-0505

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

    Published: 8 Feb 2022
    5.4
    Medium

    CVE-2022-0506

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

    Published: 8 Feb 2022
    5.5
    Medium

    CVE-2021-0145

    Last Modified: 5 May 2025

    Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 8 Feb 2022
    5.5
    Medium

    CVE-2021-0127

    Last Modified: 5 May 2025

    Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 8 Feb 2022
    7.8
    High

    CVE-2022-0523

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

    Published: 8 Feb 2022
    5.4
    Medium

    CVE-2021-33120

    Last Modified: 5 May 2025

    Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.

    Published: 8 Feb 2022
    6.3
    Medium

    CVE-2022-21703

    Last Modified: 23 Apr 2025

    Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Published: 8 Feb 2022
    6.5
    Medium

    CVE-2022-22760

    Last Modified: 16 Apr 2025

    When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

    Published: 8 Feb 2022
    8.8
    High

    CVE-2022-22764

    Last Modified: 16 Apr 2025

    Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

    Published: 8 Feb 2022
    8.8
    High

    CVE-2022-22761

    Last Modified: 16 Apr 2025

    Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

    Published: 8 Feb 2022
    8.8
    High

    CVE-2022-22763

    Last Modified: 16 Apr 2025

    When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.

    Published: 8 Feb 2022
    9.6
    Critical

    CVE-2022-22759

    Last Modified: 16 Apr 2025

    If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

    Published: 8 Feb 2022
    6.5
    Medium

    CVE-2022-21702

    Last Modified: 22 Apr 2025

    Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource for a specific Grafana instance or either set up its own public service and instruct anyone to set it up in their Grafana instance. To be impacted, all of the following must be applicable. For the data source proxy: A Grafana HTTP-based datasource configured with Server as Access Mode and a URL set, the attacker has to be in control of the HTTP server serving the URL of above datasource, and a specially crafted link pointing at the attacker controlled data source must be clicked on by an authenticated user. For the plugin proxy: A Grafana HTTP-based app plugin configured and enabled with a URL set, the attacker has to be in control of the HTTP server serving the URL of above app, and a specially crafted link pointing at the attacker controlled plugin must be clocked on by an authenticated user. For the backend plugin resource: An attacker must be able to navigate an authenticated user to a compromised plugin through a crafted link. Users are advised to update to a patched version. There are no known workarounds for this vulnerability.

    Published: 8 Feb 2022
    4.3
    Medium

    CVE-2022-21713

    Last Modified: 23 Apr 2025

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Published: 8 Feb 2022