CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-46496

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_ObjFree in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46494

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueLookupBase in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46495

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via DeleteTreeValue in src/jsiObj.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46492

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_FunctionInvoke at src/jsiFunc.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46490

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a SEGV vulnerability via NumberConstructor at src/jsiNumber.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46491

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_CommandPkgOpts at src/jsiCmds.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46489

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_DecrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46488

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArrayConcatCmd at src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46487

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e506. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46486

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArraySpliceCmd at src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46484

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_IncrRefCount in src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    5.5
    Medium

    CVE-2021-46485

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_ValueIsNumber at src/jsiValue.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 27 Jan 2022
    7.8
    High

    CVE-2022-22942

    Last Modified: 21 Nov 2024

    The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer.

    Published: 27 Jan 2022
    9.8
    Critical

    CVE-2021-46428

    Last Modified: 21 Nov 2024

    A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.

    Published: 27 Jan 2022
    9.8
    Critical

    CVE-2021-46427

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

    Published: 27 Jan 2022
    7.5
    High

    CVE-2021-46102

    Last Modified: 21 Nov 2024

    From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating the variable "addr" via "addr = (sym.st_value + refd_pa) as u64";

    Published: 27 Jan 2022
    9.8
    Critical

    CVE-2021-46377

    Last Modified: 21 Nov 2024

    There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser

    Published: 27 Jan 2022
    8.8
    High

    CVE-2021-46097

    Last Modified: 21 Nov 2024

    Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log

    Published: 27 Jan 2022
    7.2
    High

    CVE-2021-46088

    Last Modified: 21 Nov 2024

    Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

    Published: 27 Jan 2022
    4.8
    Medium

    CVE-2021-46065

    Last Modified: 21 Nov 2024

    A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.

    Published: 27 Jan 2022
    5.4
    Medium

    CVE-2022-0348

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.

    Published: 27 Jan 2022
    5.3
    Medium

    CVE-2021-28096

    Last Modified: 21 Nov 2024

    An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections.

    Published: 27 Jan 2022
    5.3
    Medium

    CVE-2021-44795

    Last Modified: 18 May 2026

    Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitation of this vulnerability might allow a remote attacker to delete permissions from other users without authenticating.

    Published: 27 Jan 2022
    5.3
    Medium

    CVE-2021-44794

    Last Modified: 18 May 2026

    Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could exploit this vulnerability to access the device information page. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information.

    Published: 27 Jan 2022
    8.6
    High

    CVE-2021-44793

    Last Modified: 18 May 2026

    Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.

    Published: 27 Jan 2022
    5.3
    Medium

    CVE-2021-44792

    Last Modified: 18 May 2026

    Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could exploit this vulnerability to access the logging interface. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information.

    Published: 27 Jan 2022
    —
    Unknown

    CVE-2021-44121

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 27 Jan 2022
    5.4
    Medium

    CVE-2022-0372

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.

    Published: 27 Jan 2022
    5.4
    Medium

    CVE-2022-0370

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

    Published: 27 Jan 2022
    7.5
    High

    CVE-2022-22828

    Last Modified: 21 Nov 2024

    An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.

    Published: 27 Jan 2022
    5.4
    Medium

    CVE-2022-0387

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

    Published: 27 Jan 2022
    7.5
    High

    CVE-2022-23596

    Last Modified: 5 May 2025

    Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users. The problem is patched in 7.4.1. There are no known workarounds and users are advised to upgrade as soon as possible.

    Published: 27 Jan 2022
    9.1
    Critical

    CVE-2022-21723

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.

    Published: 27 Jan 2022
    9.1
    Critical

    CVE-2022-21722

    Last Modified: 4 Nov 2025

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.

    Published: 27 Jan 2022
    7.5
    High

    CVE-2021-4091

    Last Modified: 3 Nov 2025

    A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

    Published: 27 Jan 2022
    4.8
    Medium

    CVE-2022-0485

    Last Modified: 21 Nov 2024

    A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.

    Published: 27 Jan 2022
    4.2
    Medium

    CVE-2022-0532

    Last Modified: 21 Nov 2024

    An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.

    Published: 27 Jan 2022
    7.8
    High

    CVE-2022-1998

    Last Modified: 21 Nov 2024

    A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

    Published: 27 Jan 2022
    4.3
    Medium

    CVE-2021-41166

    Last Modified: 23 Apr 2025

    The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANAGE_DOCUMENTS` permission may view image thumbnails for images it does not have permission to view. Version 3.17.1 contains a patch. There are no known workarounds.

    Published: 26 Jan 2022
    8.8
    High

    CVE-2021-32849

    Last Modified: 22 Apr 2025

    Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.

    Published: 26 Jan 2022
    4
    Medium

    CVE-2021-32841

    Last Modified: 22 Apr 2025

    SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that `destDir` ends with slash. If the `destDir` is not slash terminated like `/home/user/dir` it is possible to create a file with a name thats begins with the destination directory, i.e. `/home/user/dir.sh`. Because of the file name and destination directory constraints, the arbitrary file creation impact is limited and depends on the use case. Version 1.3.3 contains a patch for this vulnerability.

    Published: 26 Jan 2022
    4
    Medium

    CVE-2021-32842

    Last Modified: 22 Apr 2025

    SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that `_baseDirectory` ends with slash. If the _baseDirectory is not slash terminated like `/home/user/dir` it is possible to create a file with a name thats begins as the destination directory one level up from the directory, i.e. `/home/user/dir.sh`. Because of the file name and destination directory constraints, the arbitrary file creation impact is limited and depends on the use case. Version 1.3.3 fixed this vulnerability.

    Published: 26 Jan 2022
    7.3
    High

    CVE-2021-32840

    Last Modified: 22 Apr 2025

    SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.

    Published: 26 Jan 2022
    9
    Critical

    CVE-2022-21686

    Last Modified: 23 Apr 2025

    PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2022-22852

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list.

    Published: 26 Jan 2022
    8.8
    High

    CVE-2021-46114

    Last Modified: 21 Nov 2024

    jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

    Published: 26 Jan 2022
    7.5
    High

    CVE-2021-46385

    Last Modified: 21 Nov 2024

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2022-22850

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types.

    Published: 26 Jan 2022
    6.1
    Medium

    CVE-2022-23993

    Last Modified: 21 Nov 2024

    /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.

    Published: 26 Jan 2022
    7.2
    High

    CVE-2021-46561

    Last Modified: 21 Nov 2024

    controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context of that new organization.

    Published: 26 Jan 2022