CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-46230

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46231

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46233

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46232

    Last Modified: 21 Nov 2024

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46452

    Last Modified: 21 Nov 2024

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_address, tomography_ping_number, tomography_ping_size, tomography_ping_timeout, and tomography_ping_ttl parameters.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46453

    Last Modified: 21 Nov 2024

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46454

    Last Modified: 21 Nov 2024

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulnerability allows attackers to execute arbitrary commands via the ApCliKeyStr parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46456

    Last Modified: 21 Nov 2024

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerability allows attackers to execute arbitrary commands via the wl(0).(0)_maclist parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46455

    Last Modified: 21 Nov 2024

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerability allows attackers to execute arbitrary commands via the station_access_enable parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2021-46457

    Last Modified: 21 Nov 2024

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24142

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the firewallEn parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24144

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary commands via the gateway, dns1, and dns2 parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24143

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24145

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a Denial of Service (DoS) via the security and security_5g parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24146

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24147

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS) via the wanMTU, wanSpeed, cloneType, mac, and serviceName parameters.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24148

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24149

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWirelessRepeat. This vulnerability allows attackers to cause a Denial of Service (DoS) via the wpapsk_crypto parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24151

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the shareSpeed parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24150

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows attackers to execute arbitrary commands via the remoteIp parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24152

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetRouteStatic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24153

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formAddMacfilterRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24154

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetRebootTimer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the rebootTime parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24155

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a heap overflow in the function setSchedWifi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the schedStartTime and schedEndTime parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24156

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24157

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetMacFilterCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceList parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24158

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24159

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetPPTPServer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the startIp and endIp parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24162

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24160

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetDeviceName. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24161

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a heap overflow in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mac parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24164

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsHijackRule parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24163

    Last Modified: 21 Nov 2024

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24165

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24166

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the manualTime parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24167

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24168

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24169

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindAdd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRule parameter.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24170

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.

    Published: 4 Feb 2022
    9.8
    Critical

    CVE-2022-24171

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-24172

    Last Modified: 21 Nov 2024

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.

    Published: 4 Feb 2022
    7.5
    High

    CVE-2022-23913

    Last Modified: 15 Jun 2026

    In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

    Published: 4 Feb 2022
    7.8
    High

    CVE-2022-26129

    Last Modified: 4 Nov 2025

    Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

    Published: 4 Feb 2022
    7.8
    High

    CVE-2022-26128

    Last Modified: 4 Nov 2025

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.

    Published: 4 Feb 2022
    6.3
    Medium

    CVE-2021-40403

    Last Modified: 15 Apr 2025

    An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 4 Feb 2022
    5.5
    Medium

    CVE-2021-4043

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

    Published: 4 Feb 2022
    —
    Unknown

    CVE-2022-24425

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Feb 2022
    —
    Unknown

    CVE-2022-24427

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Feb 2022
    8.6
    High

    CVE-2021-40401

    Last Modified: 15 Apr 2025

    A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 4 Feb 2022
    3.3
    Low

    CVE-2022-24448

    Last Modified: 21 Nov 2024

    An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.

    Published: 4 Feb 2022