CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-23019

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23021

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit HTTP Proxy in HTTP Profile. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23020

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23025

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    6.5
    Medium

    CVE-2022-23023

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23024

    Last Modified: 21 Nov 2024

    On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23022

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    4.3
    Medium

    CVE-2022-23026

    Last Modified: 21 Nov 2024

    On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23017

    Last Modified: 21 Nov 2024

    On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23018

    Last Modified: 21 Nov 2024

    On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2022-23013

    Last Modified: 21 Nov 2024

    On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23012

    Last Modified: 21 Nov 2024

    On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23015

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processing SSL traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23016

    Last Modified: 21 Nov 2024

    On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    6.5
    Medium

    CVE-2022-23014

    Last Modified: 21 Nov 2024

    On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23011

    Last Modified: 21 Nov 2024

    On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23010

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    5.4
    Medium

    CVE-2022-23008

    Last Modified: 21 Nov 2024

    On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    7.2
    High

    CVE-2022-23009

    Last Modified: 21 Nov 2024

    On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2021-43298

    Last Modified: 21 Nov 2024

    The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized (401) response.

    Published: 25 Jan 2022
    5.4
    Medium

    CVE-2021-45729

    Last Modified: 20 Feb 2025

    The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.

    Published: 25 Jan 2022
    4.2
    Medium

    CVE-2021-40337

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2022-0335

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

    Published: 25 Jan 2022
    4.3
    Medium

    CVE-2022-0334

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.

    Published: 25 Jan 2022
    3.8
    Low

    CVE-2022-0333

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2022-0332

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2022-0270

    Last Modified: 21 Nov 2024

    Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.

    Published: 25 Jan 2022
    6.1
    Medium

    CVE-2022-22789

    Last Modified: 21 Nov 2024

    Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for all the users. The xx_users.ini file in the FormStorm folder contains usernames in cleartext and an obfuscated password. Malicious user can take over an account by replacing existing password in the file.

    Published: 25 Jan 2022
    3.3
    Low

    CVE-2021-38129

    Last Modified: 21 Nov 2024

    Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and including 12.21. The vulnerability could be exploited by a non-privileged local user to access system monitoring data collected by Operations Agent.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-40167

    Last Modified: 21 Nov 2024

    A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-4034

    Last Modified: 6 Nov 2025

    A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-39031

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to unauthorized resources. IBM X-Force ID: 213875.

    Published: 25 Jan 2022
    5.4
    Medium

    CVE-2021-46087

    Last Modified: 21 Nov 2024

    In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.

    Published: 25 Jan 2022
    6.5
    Medium

    CVE-2021-46085

    Last Modified: 21 Nov 2024

    OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.

    Published: 25 Jan 2022
    5.4
    Medium

    CVE-2021-46083

    Last Modified: 21 Nov 2024

    uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code.

    Published: 25 Jan 2022
    5.4
    Medium

    CVE-2021-46084

    Last Modified: 21 Nov 2024

    uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2021-46086

    Last Modified: 21 Nov 2024

    xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in the packet to destroy real data.

    Published: 25 Jan 2022
    6.5
    Medium

    CVE-2021-34870

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP messages. The issue results from a lack of authentication required for a privileged request. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13325.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-34869

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of user-supplied data, which can result in an uncontrolled memory allocation. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13797.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-34868

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of user-supplied data, which can result in an uncontrolled memory allocation. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13712.

    Published: 25 Jan 2022
    8.2
    High

    CVE-2021-34867

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of user-supplied data, which can result in an uncontrolled memory allocation. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-13672.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-34865

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-13313.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2021-43863

    Last Modified: 23 Apr 2025

    The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContentProvider` and `DiskLruImageCacheFileProvider` have security issues (an SQL injection, and an insufficient permission control, respectively) that allow malicious apps in the same device to access Nextcloud's data bypassing the permission control system. Users should upgrade to version 3.18.1 to receive a patch. There are no known workarounds aside from upgrading.

    Published: 25 Jan 2022
    6.1
    Medium

    CVE-2021-46034

    Last Modified: 21 Nov 2024

    A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2021-46033

    Last Modified: 21 Nov 2024

    In ForestBlog, as of 2021-12-28, File upload can bypass verification.

    Published: 25 Jan 2022
    9.1
    Critical

    CVE-2021-3850

    Last Modified: 21 Nov 2024

    Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2021-46089

    Last Modified: 21 Nov 2024

    In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.

    Published: 25 Jan 2022
    6.3
    Medium

    CVE-2022-21697

    Last Modified: 23 Apr 2025

    Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to Server-Side Request Forgery (SSRF). Any user deploying Jupyter Server or Notebook with jupyter-proxy-server extension enabled is affected. A lack of input validation allows authenticated clients to proxy requests to other hosts, bypassing the `allowed_hosts` check. Because authentication is required, which already grants permissions to make the same requests via kernel or terminal execution, this is considered low to moderate severity. Users may upgrade to version 3.2.1 to receive a patch or, as a workaround, install the patch manually.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-45847

    Last Modified: 21 Nov 2024

    Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to cause an application crash using a crafted 3MF input file.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-45846

    Last Modified: 21 Nov 2024

    A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF document, where a metadata tag lacks a "type" attribute.

    Published: 25 Jan 2022