CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-23945

    Last Modified: 21 Nov 2024

    Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

    Published: 25 Jan 2022
    9.1
    Critical

    CVE-2022-23944

    Last Modified: 21 Nov 2024

    User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

    Published: 25 Jan 2022
    7.5
    High

    CVE-2022-23223

    Last Modified: 21 Nov 2024

    On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2021-45029

    Last Modified: 21 Nov 2024

    Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-46113

    Last Modified: 21 Nov 2024

    In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-45803

    Last Modified: 21 Nov 2024

    MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2021-45802

    Last Modified: 21 Nov 2024

    MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-45845

    Last Modified: 21 Nov 2024

    The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-45844

    Last Modified: 21 Nov 2024

    Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

    Published: 25 Jan 2022
    6.5
    Medium

    CVE-2021-45340

    Last Modified: 24 Apr 2026

    In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

    Published: 25 Jan 2022
    5.4
    Medium

    CVE-2022-0268

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.

    Published: 25 Jan 2022
    4.3
    Medium

    CVE-2022-0338

    Last Modified: 24 Feb 2026

    Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2022-23935

    Last Modified: 21 Nov 2024

    lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-46483

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-46481

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-46482

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-46480

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-46478

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-46475

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-46477

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-46474

    Last Modified: 21 Nov 2024

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-44994

    Last Modified: 21 Nov 2024

    There is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerryscript 3.0.0.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-44993

    Last Modified: 21 Nov 2024

    There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript 3.0.0.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-44992

    Last Modified: 21 Nov 2024

    There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-44988

    Last Modified: 21 Nov 2024

    Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2022-23034

    Last Modified: 21 Nov 2024

    A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping, unmapping of such a mapping can be requested in two steps. The reference count for such a mapping would then mistakenly be decremented twice. Underflow of the counters gets detected, resulting in the triggering of a hypervisor bug check.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2022-23033

    Last Modified: 21 Nov 2024

    arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do not actually clear the pagetable entry if the entry doesn't have the valid bit set. It is possible to have a valid pagetable entry without the valid bit set when a guest operating system uses set/way cache maintenance instructions. For instance, a guest issuing a set/way cache maintenance instruction, then calling the XENMEM_decrease_reservation hypercall to give back memory pages to Xen, might be able to retain access to those pages even after Xen started reusing them for other purposes.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-40159

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-45342

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2021-45343

    Last Modified: 21 Nov 2024

    In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2022-0358

    Last Modified: 21 Nov 2024

    A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.

    Published: 25 Jan 2022
    7.1
    High

    CVE-2022-0393

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

    Published: 25 Jan 2022
    5.5
    Medium

    CVE-2022-24959

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2021-40158

    Last Modified: 21 Nov 2024

    A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 25 Jan 2022
    8.8
    High

    CVE-2021-45341

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2022-0330

    Last Modified: 21 Nov 2024

    A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.

    Published: 25 Jan 2022
    4.6
    Medium

    CVE-2022-23035

    Last Modified: 21 Nov 2024

    Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not quiescent yet at the time this cleanup gets invoked, the cleanup attempt may be scheduled to be retried. When multiple interrupts are involved, this scheduling of a retry may get erroneously skipped. At the same time pointers may get cleared (resulting in a de-reference of NULL) and freed (resulting in a use-after-free), while other code would continue to assume them to be valid.

    Published: 25 Jan 2022
    9.1
    Critical

    CVE-2022-23959

    Last Modified: 21 Nov 2024

    In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.

    Published: 25 Jan 2022
    7.8
    High

    CVE-2022-0392

    Last Modified: 3 Nov 2025

    Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.

    Published: 25 Jan 2022
    9.8
    Critical

    CVE-2021-43394

    Last Modified: 21 Nov 2024

    Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.

    Published: 24 Jan 2022
    —
    Unknown

    CVE-2022-0177

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jan 2022
    8.2
    High

    CVE-2022-22554

    Last Modified: 21 Nov 2024

    Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.

    Published: 24 Jan 2022
    6
    Medium

    CVE-2021-43589

    Last Modified: 21 Nov 2024

    Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the Unity underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.

    Published: 24 Jan 2022
    4.3
    Medium

    CVE-2021-43588

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 24 Jan 2022
    4.3
    Medium

    CVE-2021-36349

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts.

    Published: 24 Jan 2022
    7.5
    High

    CVE-2021-36343

    Last Modified: 23 Feb 2026

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 24 Jan 2022
    7.5
    High

    CVE-2021-36342

    Last Modified: 23 Feb 2026

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-45224

    Last Modified: 21 Nov 2024

    An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-45225

    Last Modified: 21 Nov 2024

    An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affecting the search window and activity view window).

    Published: 24 Jan 2022
    6.5
    Medium

    CVE-2021-45226

    Last Modified: 21 Nov 2024

    An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites.

    Published: 24 Jan 2022