CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2022-24380

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 4 Feb 2022
    —
    Unknown

    CVE-2022-21130

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 4 Feb 2022
    8.8
    High

    CVE-2022-24262

    Last Modified: 21 Nov 2024

    The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24259

    Last Modified: 21 Nov 2024

    An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24260

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-44977

    Last Modified: 21 Nov 2024

    In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-44978

    Last Modified: 21 Nov 2024

    iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.

    Published: 4 Feb 2022
    8.8
    High

    CVE-2021-46398

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.

    Published: 4 Feb 2022
    8.1
    High

    CVE-2021-43145

    Last Modified: 21 Nov 2024

    With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts.

    Published: 4 Feb 2022
    5.3
    Medium

    CVE-2021-44886

    Last Modified: 21 Nov 2024

    In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't have the same permissions as the original agent, they could receive ticket notifications for tickets that they have no access to.

    Published: 4 Feb 2022
    7.7
    High

    CVE-2022-24348

    Last Modified: 21 Nov 2024

    Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.

    Published: 4 Feb 2022
    4.9
    Medium

    CVE-2021-44983

    Last Modified: 21 Nov 2024

    In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-46320

    Last Modified: 21 Nov 2024

    In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an initializer has finished running it can never be re-executed. However, an exception put in place to support multiple inheritance made reentrancy possible, breaking the expectation that there is a single execution.

    Published: 4 Feb 2022
    4.9
    Medium

    CVE-2022-23316

    Last Modified: 21 Nov 2024

    An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.

    Published: 4 Feb 2022
    7.8
    High

    CVE-2021-44903

    Last Modified: 21 Nov 2024

    Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLib.sys, NTIOLib_X64.sys, WinRing0.sys, WinRing0x64.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL requests.

    Published: 4 Feb 2022
    7.8
    High

    CVE-2021-44901

    Last Modified: 21 Nov 2024

    Micro-Star International (MSI) Dragon Center <= 2.0.116.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLib.sys, NTIOLib_X64.sys, WinRing0.sys, WinRing0x64.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL requests.

    Published: 4 Feb 2022
    7.8
    High

    CVE-2021-44900

    Last Modified: 21 Nov 2024

    Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the NTIOLib_X64.sys and BstkDrv_msi2.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL requests.

    Published: 4 Feb 2022
    7.8
    High

    CVE-2021-44899

    Last Modified: 21 Nov 2024

    Micro-Star International (MSI) Center <= 1.0.31.0 is vulnerable to multiple Privilege Escalation vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLib.sys, NTIOLib_X64.sys, WinRing0.sys, WinRing0x64.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL requests.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-44246

    Last Modified: 21 Nov 2024

    Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IpTo parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-44247

    Last Modified: 21 Nov 2024

    Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-44880

    Last Modified: 21 Nov 2024

    D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-44881

    Last Modified: 21 Nov 2024

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-44882

    Last Modified: 21 Nov 2024

    D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45733

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45734

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45735

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to use the HTTP protocol for authentication into the admin interface, allowing attackers to intercept user credentials via packet capture software.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45736

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45737

    Last Modified: 21 Nov 2024

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the Host parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45739

    Last Modified: 21 Nov 2024

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45738

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45740

    Last Modified: 21 Nov 2024

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45741

    Last Modified: 21 Nov 2024

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setIpv6Cfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the relay6to4 parameters.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45742

    Last Modified: 21 Nov 2024

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45986

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45987

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45988

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsForwardRule parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45990

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45989

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qosGuestUpstream and qosGuestDownstream parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45991

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddVpnUsers. This vulnerability allows attackers to cause a Denial of Service (DoS) via the vpnUsers parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45992

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qvlanName parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45993

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindModify. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRuleIP and IPMacBindRuleMac parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45994

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formDelDhcpRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the delDhcpIndex parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45995

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allows attackers to cause a Denial of Service (DoS) via the staticRouteNet, staticRouteMask, and staticRouteGateway parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45996

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2021-45997

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-45998

    Last Modified: 21 Nov 2024

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46226

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46227

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46228

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46229

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.

    Published: 4 Feb 2022