CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-43522

    Last Modified: 11 Aug 2026

    An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A StorageSecurityCommandDxe SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.

    Published: 2 Feb 2022
    5.3
    Medium

    CVE-2021-39021

    Last Modified: 21 Nov 2024

    IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which could facilitate username enumeration. IBM X-Force ID: 213856.

    Published: 2 Feb 2022
    6.1
    Medium

    CVE-2022-0432

    Last Modified: 21 Nov 2024

    Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.

    Published: 2 Feb 2022
    7.5
    High

    CVE-2021-42642

    Last Modified: 21 Nov 2024

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.

    Published: 2 Feb 2022
    7.5
    High

    CVE-2021-42641

    Last Modified: 21 Nov 2024

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.

    Published: 2 Feb 2022
    9.1
    Critical

    CVE-2021-42640

    Last Modified: 21 Nov 2024

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

    Published: 2 Feb 2022
    6.1
    Medium

    CVE-2021-42639

    Last Modified: 21 Nov 2024

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.

    Published: 2 Feb 2022
    9.8
    Critical

    CVE-2021-42637

    Last Modified: 21 Nov 2024

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

    Published: 2 Feb 2022
    5.3
    Medium

    CVE-2021-42633

    Last Modified: 21 Nov 2024

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.

    Published: 2 Feb 2022
    7.5
    High

    CVE-2022-22510

    Last Modified: 21 Nov 2024

    Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.

    Published: 2 Feb 2022
    8.8
    High

    CVE-2022-22509

    Last Modified: 21 Nov 2024

    In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

    Published: 2 Feb 2022
    9.3
    Critical

    CVE-2022-21817

    Last Modified: 21 Nov 2024

    NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.

    Published: 2 Feb 2022
    9.8
    Critical

    CVE-2021-39070

    Last Modified: 21 Nov 2024

    IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.

    Published: 2 Feb 2022
    8.8
    High

    CVE-2021-39066

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.

    Published: 2 Feb 2022
    8.8
    High

    CVE-2021-39044

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.

    Published: 2 Feb 2022
    9.1
    Critical

    CVE-2021-24043

    Last Modified: 21 Nov 2024

    A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if a user sent a malformed RTCP packet during an established call.

    Published: 2 Feb 2022
    5.3
    Medium

    CVE-2020-26208

    Last Modified: 5 May 2025

    JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras. In affected versions there is a heap-buffer-overflow on jhead-3.04/jpgfile.c:285 ReadJpegSections. Crafted jpeg images can be provided to the user resulting in a program crash or potentially incorrect exif information retrieval. Users are advised to upgrade. There is no known workaround for this issue.

    Published: 2 Feb 2022
    8.8
    High

    CVE-2022-0366

    Last Modified: 21 Nov 2024

    An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

    Published: 2 Feb 2022
    8.8
    High

    CVE-2021-41018

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.

    Published: 2 Feb 2022
    6.7
    Medium

    CVE-2021-36193

    Last Modified: 13 Jan 2026

    Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted commands.

    Published: 2 Feb 2022
    6.1
    Medium

    CVE-2021-43062

    Last Modified: 21 Nov 2024

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the FortiGuard URI protection service.

    Published: 2 Feb 2022
    8.8
    High

    CVE-2021-43073

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.

    Published: 2 Feb 2022
    7.8
    High

    CVE-2021-41016

    Last Modified: 21 Nov 2024

    A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special characters

    Published: 2 Feb 2022
    4.2
    Medium

    CVE-2021-36177

    Last Modified: 21 Nov 2024

    An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x may allow an attacker on the same vlan as the HA management interface to make an unauthenticated direct connection to the FAC's database.

    Published: 2 Feb 2022
    8.1
    High

    CVE-2021-42753

    Last Modified: 21 Nov 2024

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and directory deletion in the device filesystem.

    Published: 2 Feb 2022
    9.8
    Critical

    CVE-2022-24300

    Last Modified: 21 Nov 2024

    Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.

    Published: 2 Feb 2022
    6.5
    Medium

    CVE-2022-24301

    Last Modified: 21 Nov 2024

    In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.

    Published: 2 Feb 2022
    7.8
    High

    CVE-2022-26127

    Last Modified: 4 Nov 2025

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.

    Published: 2 Feb 2022
    7.8
    High

    CVE-2022-0443

    Last Modified: 21 Nov 2024

    Use After Free in GitHub repository vim/vim prior to 8.2.

    Published: 2 Feb 2022
    8.1
    High

    CVE-2021-42638

    Last Modified: 21 Nov 2024

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-24220

    Last Modified: 21 Nov 2024

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-24223

    Last Modified: 21 Nov 2024

    AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-24222

    Last Modified: 21 Nov 2024

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-24221

    Last Modified: 21 Nov 2024

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-24219

    Last Modified: 21 Nov 2024

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

    Published: 1 Feb 2022
    9.1
    Critical

    CVE-2022-24218

    Last Modified: 21 Nov 2024

    An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2021-46093

    Last Modified: 21 Nov 2024

    eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-38560

    Last Modified: 21 Nov 2024

    Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

    Published: 1 Feb 2022
    5.3
    Medium

    CVE-2021-44746

    Last Modified: 21 Nov 2024

    UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote attacker who can access to the internal network, the configuration information may be obtained.

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2021-44451

    Last Modified: 21 Nov 2024

    Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2021-43510

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2021-43509

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.

    Published: 1 Feb 2022
    5.4
    Medium

    CVE-2021-46253

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-45416

    Last Modified: 21 Nov 2024

    Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-0401

    Last Modified: 21 Nov 2024

    Path Traversal in NPM w-zip prior to 1.0.12.

    Published: 1 Feb 2022
    9.8
    Critical

    CVE-2022-0320

    Last Modified: 21 Nov 2024

    The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2022-0220

    Last Modified: 21 Nov 2024

    The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)

    Published: 1 Feb 2022
    6.5
    Medium

    CVE-2021-25092

    Last Modified: 21 Nov 2024

    The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack

    Published: 1 Feb 2022
    7.5
    High

    CVE-2021-25093

    Last Modified: 21 Nov 2024

    The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

    Published: 1 Feb 2022
    6.1
    Medium

    CVE-2021-25091

    Last Modified: 21 Nov 2024

    The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

    Published: 1 Feb 2022