CVE Feed

    Dashboard / CVE

    7.7
    High

    CVE-2021-44361

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Set3G param is not object. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.7
    High

    CVE-2021-44359

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetCrop param is not object. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.7
    High

    CVE-2021-44358

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetRec param is not object. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.3
    High

    CVE-2021-23558

    Last Modified: 21 Nov 2024

    The package bmoor before 0.10.1 are vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)

    Published: 28 Jan 2022
    5.4
    Medium

    CVE-2022-0395

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

    Published: 28 Jan 2022
    5.6
    Medium

    CVE-2021-23760

    Last Modified: 21 Nov 2024

    The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-28272](https://security.snyk.io/vuln/SNYK-JS-KEYGET-1048048)

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2021-23484

    Last Modified: 21 Nov 2024

    The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2021-46448

    Last Modified: 21 Nov 2024

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.

    Published: 28 Jan 2022
    5.4
    Medium

    CVE-2021-46447

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in H.H.G Multistore v5.1.0 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the State parameter under the Address Book module.

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2021-46446

    Last Modified: 21 Nov 2024

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2021-46444

    Last Modified: 21 Nov 2024

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID.

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2021-46445

    Last Modified: 21 Nov 2024

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.

    Published: 28 Jan 2022
    6.1
    Medium

    CVE-2022-0352

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.

    Published: 28 Jan 2022
    5.3
    Medium

    CVE-2022-23889

    Last Modified: 21 Nov 2024

    The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.

    Published: 28 Jan 2022
    8.8
    High

    CVE-2022-23888

    Last Modified: 21 Nov 2024

    YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.

    Published: 28 Jan 2022
    6.5
    Medium

    CVE-2022-23887

    Last Modified: 21 Nov 2024

    YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.

    Published: 28 Jan 2022
    8.8
    High

    CVE-2022-22994

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.

    Published: 28 Jan 2022
    7.8
    High

    CVE-2022-22992

    Last Modified: 21 Nov 2024

    A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

    Published: 28 Jan 2022
    7.2
    High

    CVE-2021-40412

    Last Modified: 15 Apr 2025

    An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated properly. This would lead to an OS command injection.

    Published: 28 Jan 2022
    7.2
    High

    CVE-2021-40410

    Last Modified: 15 Apr 2025

    An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_data->dns1 variable, that has the value of the dns1 parameter provided through the SetLocal API, is not validated properly. This would lead to an OS command injection.

    Published: 28 Jan 2022
    7.2
    High

    CVE-2021-40411

    Last Modified: 15 Apr 2025

    An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_data->dns2 variable, that has the value of the dns2 parameter provided through the SetLocalLink API, is not validated properly. This would lead to an OS command injection.

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2021-40409

    Last Modified: 15 Apr 2025

    An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2021-40408

    Last Modified: 15 Apr 2025

    An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->username variable, that has the value of the userName parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.

    Published: 28 Jan 2022
    7.2
    High

    CVE-2021-40407

    Last Modified: 3 Nov 2025

    An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    8.8
    High

    CVE-2021-40416

    Last Modified: 15 Apr 2025

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    6.5
    Medium

    CVE-2021-40415

    Last Modified: 15 Apr 2025

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will default to 7. This will give non-administrative users the possibility to format the SD card and reboot the device.

    Published: 28 Jan 2022
    7.1
    High

    CVE-2021-40413

    Last Modified: 15 Apr 2025

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version is new, it would be possible, allegedly, to later on perform the Upgrade. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.1
    High

    CVE-2021-40414

    Last Modified: 15 Apr 2025

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sensitivity of the camera per a range of hours, and which of the camera spaces to ignore when considering movement detection. Because in cgi_check_ability the SetMdAlarm API does not have a specific case, the user permission will default to 7. This will give non-administrative users the possibility to change the movement detection parameters.

    Published: 28 Jan 2022
    9.8
    Critical

    CVE-2022-21217

    Last Modified: 15 Apr 2025

    An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.5
    High

    CVE-2021-40406

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.5
    High

    CVE-2021-40419

    Last Modified: 15 Apr 2025

    A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 28 Jan 2022
    6.5
    Medium

    CVE-2021-40404

    Last Modified: 15 Apr 2025

    An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.5
    High

    CVE-2022-21134

    Last Modified: 15 Apr 2025

    A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 28 Jan 2022
    5.9
    Medium

    CVE-2022-21199

    Last Modified: 15 Apr 2025

    An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

    Published: 28 Jan 2022
    7.5
    High

    CVE-2022-21801

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to a reboot. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 28 Jan 2022
    8.2
    High

    CVE-2022-21796

    Last Modified: 15 Apr 2025

    A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.5
    High

    CVE-2021-40423

    Last Modified: 15 Apr 2025

    A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of HTTP requests can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    7.5
    High

    CVE-2022-21236

    Last Modified: 15 Apr 2025

    An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 28 Jan 2022
    5.5
    Medium

    CVE-2022-23456

    Last Modified: 21 Nov 2024

    Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.

    Published: 28 Jan 2022
    3.7
    Low

    CVE-2021-40340

    Last Modified: 21 Nov 2024

    Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a reconnaissance for further exploitation. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

    Published: 28 Jan 2022
    3.7
    Low

    CVE-2021-40339

    Last Modified: 21 Nov 2024

    Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

    Published: 28 Jan 2022
    3.7
    Low

    CVE-2021-40338

    Last Modified: 21 Nov 2024

    Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

    Published: 28 Jan 2022
    4.8
    Medium

    CVE-2022-23979

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).

    Published: 28 Jan 2022
    6.8
    Medium

    CVE-2021-31567

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to escape from the web server home directory and download any file within the OS.

    Published: 28 Jan 2022
    6.1
    Medium

    CVE-2021-23863

    Last Modified: 21 Nov 2024

    HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker.

    Published: 28 Jan 2022
    3.4
    Low

    CVE-2021-23174

    Last Modified: 20 Feb 2025

    Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

    Published: 28 Jan 2022
    6.6
    Medium

    CVE-2022-22791

    Last Modified: 21 Nov 2024

    SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stealing of cookies, loading of HTML tags and JS code onto the system.

    Published: 28 Jan 2022
    5.6
    Medium

    CVE-2022-22790

    Last Modified: 21 Nov 2024

    SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" parameter the attacker can return to the root directory and open the host file. The path exposes sensitive files that users upload

    Published: 28 Jan 2022
    8.1
    High

    CVE-2021-44463

    Last Modified: 17 Apr 2025

    Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

    Published: 28 Jan 2022
    6.1
    Medium

    CVE-2021-26264

    Last Modified: 17 Apr 2025

    A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.

    Published: 28 Jan 2022