CVE Feed

    Dashboard / CVE

    2.7
    Low

    CVE-2021-29846

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.

    Published: 26 Jan 2022
    8.8
    High

    CVE-2021-29845

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. IBM X-Force ID: 205255.

    Published: 26 Jan 2022
    5.9
    Medium

    CVE-2021-29838

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

    Published: 26 Jan 2022
    7.2
    High

    CVE-2021-46115

    Last Modified: 21 Nov 2024

    jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.

    Published: 26 Jan 2022
    7.2
    High

    CVE-2021-46116

    Last Modified: 21 Nov 2024

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.

    Published: 26 Jan 2022
    7.5
    High

    CVE-2021-46383

    Last Modified: 21 Nov 2024

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.

    Published: 26 Jan 2022
    7.2
    High

    CVE-2021-46118

    Last Modified: 21 Nov 2024

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2022-22851

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2021-43334

    Last Modified: 21 Nov 2024

    BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.

    Published: 26 Jan 2022
    5.3
    Medium

    CVE-2021-44692

    Last Modified: 21 Nov 2024

    BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID for their profile. This UID is their private email address with symbols removed and periods replaced with hyphens. For example. [email protected] would become /members/johndoeexample-com and [email protected] would become /members/jo-testexample-com. The members list is available to everyone and (in a default configuration) often without authentication. It is therefore trivial to collect a list of email addresses.

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2022-0378

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2022-0379

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

    Published: 26 Jan 2022
    7.2
    High

    CVE-2021-46117

    Last Modified: 21 Nov 2024

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

    Published: 26 Jan 2022
    7.8
    High

    CVE-2021-45975

    Last Modified: 21 Nov 2024

    In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on the targeted system. This file will execute when the vulnerable application launches. A successful exploit could allow the attacker to execute arbitrary code on the targeted system with local administrator privileges.

    Published: 26 Jan 2022
    9.8
    Critical

    CVE-2022-0362

    Last Modified: 21 Nov 2024

    SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

    Published: 26 Jan 2022
    5.3
    Medium

    CVE-2022-0203

    Last Modified: 21 Nov 2024

    Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

    Published: 26 Jan 2022
    8.8
    High

    CVE-2021-44123

    Last Modified: 21 Nov 2024

    SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

    Published: 26 Jan 2022
    8.8
    High

    CVE-2021-44122

    Last Modified: 21 Nov 2024

    SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2021-44120

    Last Modified: 21 Nov 2024

    SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2021-44118

    Last Modified: 21 Nov 2024

    SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2022-0251

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10.

    Published: 26 Jan 2022
    4.8
    Medium

    CVE-2022-0375

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

    Published: 26 Jan 2022
    5.4
    Medium

    CVE-2022-0374

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

    Published: 26 Jan 2022
    7.8
    High

    CVE-2022-21944

    Last Modified: 21 Nov 2024

    A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE Factory watchman versions prior to 4.9.0-9.1.

    Published: 26 Jan 2022
    7.5
    High

    CVE-2022-23968

    Last Modified: 21 Nov 2024

    Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later versions as of the date of this posting" but a 2022-01-26 vendor statement reports "the latest versions of firmware are not vulnerable to this issue."

    Published: 26 Jan 2022
    5.3
    Medium

    CVE-2019-25056

    Last Modified: 21 Nov 2024

    In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing which resources are blocked and which aren't can identify the application version and defeat the User-Agent protection mechanism.

    Published: 26 Jan 2022
    7.5
    High

    CVE-2021-46559

    Last Modified: 21 Nov 2024

    The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.

    Published: 26 Jan 2022
    9.8
    Critical

    CVE-2021-46560

    Last Modified: 21 Nov 2024

    The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.

    Published: 26 Jan 2022
    6.5
    Medium

    CVE-2021-22570

    Last Modified: 21 Apr 2025

    Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

    Published: 26 Jan 2022
    9.8
    Critical

    CVE-2021-46386

    Last Modified: 21 Nov 2024

    File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

    Published: 26 Jan 2022
    7.8
    High

    CVE-2022-0368

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

    Published: 26 Jan 2022
    7
    High

    CVE-2022-23181

    Last Modified: 21 Nov 2024

    The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.

    Published: 26 Jan 2022
    —
    Unknown

    CVE-2022-23967

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15679. Reason: This candidate is a duplicate of CVE-2019-15679. Notes: All CVE users should reference CVE-2019-15679 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 26 Jan 2022
    7.5
    High

    CVE-2022-23990

    Last Modified: 5 May 2025

    Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

    Published: 26 Jan 2022
    8.1
    High

    CVE-2021-36348

    Last Modified: 21 Nov 2024

    iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.

    Published: 25 Jan 2022
    7.2
    High

    CVE-2021-36347

    Last Modified: 21 Nov 2024

    iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system.

    Published: 25 Jan 2022
    5.3
    Medium

    CVE-2021-36346

    Last Modified: 21 Nov 2024

    Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver.

    Published: 25 Jan 2022
    7.2
    High

    CVE-2021-36296

    Last Modified: 21 Nov 2024

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

    Published: 25 Jan 2022
    7.2
    High

    CVE-2021-36295

    Last Modified: 21 Nov 2024

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2021-36294

    Last Modified: 21 Nov 2024

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-36289

    Last Modified: 21 Nov 2024

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.

    Published: 25 Jan 2022
    4.3
    Medium

    CVE-2022-23258

    Last Modified: 2 Jan 2025

    Microsoft Edge for Android Spoofing Vulnerability

    Published: 25 Jan 2022
    8.6
    High

    CVE-2021-43799

    Last Modified: 23 Apr 2025

    Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ opens; this includes port 25672, the RabbitMQ distribution port, which is used as a management port. RabbitMQ's default "cookie" which protects this port is generated using a weak PRNG, which limits the entropy of the password to at most 36 bits; in practicality, the seed for the randomizer is biased, resulting in approximately 20 bits of entropy. If other firewalls (at the OS or network level) do not protect port 25672, a remote attacker can brute-force the 20 bits of entropy in the "cookie" and leverage it for arbitrary execution of code as the rabbitmq user. They can also read all data which is sent through RabbitMQ, which includes all message traffic sent by users. Version 4.9 contains a patch for this vulnerability. As a workaround, ensure that firewalls prevent access to ports 5672 and 25672 from outside the Zulip server.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-41598

    Last Modified: 21 Nov 2024

    A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and have a user authorize the application through the web authentication flow. All permissions being granted would properly be shown during the first authorization, but if the user later updated the set of repositories the app was installed on after the GitHub App had configured additional user-level permissions, those additional permissions would not be displayed, leading to more permissions being granted than the user potentially intended. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.3 and was fixed in versions 3.2.5, 3.1.13, 3.0.21. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 25 Jan 2022
    5.3
    Medium

    CVE-2022-23029

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    5.3
    Medium

    CVE-2022-23028

    Last Modified: 21 Nov 2024

    On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when global AFM SYN cookie protection (TCP Half Open flood vector) is activated in the AFM Device Dos or DOS profile, certain types of TCP connections will fail. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    5.3
    Medium

    CVE-2022-23030

    Last Modified: 21 Nov 2024

    On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor) and TCP Segmentation Offload configuration is enabled, undisclosed requests may cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    5.3
    Medium

    CVE-2022-23032

    Last Modified: 21 Nov 2024

    In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    4.9
    Medium

    CVE-2022-23031

    Last Modified: 21 Nov 2024

    On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    5.3
    Medium

    CVE-2022-23027

    Last Modified: 21 Nov 2024

    On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022