CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2021-24968

    Last Modified: 21 Nov 2024

    The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

    Published: 24 Jan 2022
    5.4
    Medium

    CVE-2021-24965

    Last Modified: 21 Nov 2024

    The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins

    Published: 24 Jan 2022
    8
    High

    CVE-2021-24936

    Last Modified: 21 Nov 2024

    The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

    Published: 24 Jan 2022
    6.1
    Medium

    CVE-2021-24923

    Last Modified: 21 Nov 2024

    The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

    Published: 24 Jan 2022
    7.5
    High

    CVE-2021-24906

    Last Modified: 21 Nov 2024

    The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

    Published: 24 Jan 2022
    7.2
    High

    CVE-2021-24865

    Last Modified: 21 Nov 2024

    The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue

    Published: 24 Jan 2022
    7.2
    High

    CVE-2021-24858

    Last Modified: 21 Nov 2024

    The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection

    Published: 24 Jan 2022
    4.3
    Medium

    CVE-2021-24733

    Last Modified: 21 Nov 2024

    The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.

    Published: 24 Jan 2022
    8.8
    High

    CVE-2021-24696

    Last Modified: 21 Nov 2024

    The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads

    Published: 24 Jan 2022
    5.4
    Medium

    CVE-2021-24694

    Last Modified: 21 Nov 2024

    The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.

    Published: 24 Jan 2022
    4.8
    Medium

    CVE-2021-24423

    Last Modified: 21 Nov 2024

    The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

    Published: 24 Jan 2022
    8.8
    High

    CVE-2022-23858

    Last Modified: 21 Nov 2024

    A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Center build 6003 v2.

    Published: 24 Jan 2022
    6.5
    Medium

    CVE-2022-23857

    Last Modified: 21 Nov 2024

    model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2022-23855

    Last Modified: 21 Nov 2024

    An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.

    Published: 24 Jan 2022
    5.3
    Medium

    CVE-2022-23856

    Last Modified: 21 Nov 2024

    An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-30636

    Last Modified: 21 Nov 2024

    In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-26706

    Last Modified: 21 Nov 2024

    An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functions do not check for integer overflow when allocating a pool whose size exceeds the address space: Mem_PoolCreate, Mem_DynPoolCreate, and Mem_DynPoolCreateHW. Because these functions use multiplication to calculate the pool sizes, the operation may cause an integer overflow if the arguments are large enough. The resulting memory pool will be smaller than expected and may be exploited by an attacker.

    Published: 24 Jan 2022
    6.5
    Medium

    CVE-2022-23437

    Last Modified: 25 Aug 2026

    There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.

    Published: 24 Jan 2022
    7.8
    High

    CVE-2022-0361

    Last Modified: 3 Nov 2025

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 24 Jan 2022
    7.8
    High

    CVE-2022-0359

    Last Modified: 3 Nov 2025

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

    Published: 24 Jan 2022
    5.5
    Medium

    CVE-2022-0529

    Last Modified: 13 Feb 2025

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

    Published: 24 Jan 2022
    5.5
    Medium

    CVE-2022-0617

    Last Modified: 21 Nov 2024

    A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.

    Published: 24 Jan 2022
    9.8
    Critical

    CVE-2021-46024

    Last Modified: 21 Nov 2024

    Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.

    Published: 23 Jan 2022
    6.1
    Medium

    CVE-2021-45380

    Last Modified: 21 Nov 2024

    AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php

    Published: 23 Jan 2022
    6.7
    Medium

    CVE-2022-20369

    Last Modified: 21 Nov 2024

    In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel

    Published: 23 Jan 2022
    7.8
    High

    CVE-2022-23850

    Last Modified: 21 Nov 2024

    xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a crafted EPUB document.

    Published: 23 Jan 2022
    5.4
    Medium

    CVE-2021-4103

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.

    Published: 23 Jan 2022
    7.8
    High

    CVE-2022-0351

    Last Modified: 3 Nov 2025

    Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.

    Published: 23 Jan 2022
    9.8
    Critical

    CVE-2022-23852

    Last Modified: 5 May 2025

    Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

    Published: 23 Jan 2022
    5.4
    Medium

    CVE-2021-4172

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

    Published: 22 Jan 2022
    7.8
    High

    CVE-2022-0998

    Last Modified: 21 Nov 2024

    An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published: 22 Jan 2022
    4.3
    Medium

    CVE-2022-23807

    Last Modified: 21 Nov 2024

    An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

    Published: 22 Jan 2022
    6.1
    Medium

    CVE-2022-23808

    Last Modified: 5 May 2025

    An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

    Published: 22 Jan 2022
    6.5
    Medium

    CVE-2022-21708

    Last Modified: 23 Apr 2025

    graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug in the library that would allow an attacker with specifically designed queries to cause stack overflow panics. Any user with access to the GraphQL handler can send these queries and cause stack overflows. This in turn could potentially compromise the ability of the server to serve data to its users. The issue has been patched in version `v1.3.0`. The only known workaround for this issue is to disable the `graphql.MaxDepth` option from your schema which is not recommended.

    Published: 21 Jan 2022
    6.3
    Medium

    CVE-2022-21707

    Last Modified: 23 Apr 2025

    wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for inbound invocations, but with this vulnerability actor capability claims are not verified upon receiving invocations. This compromises the security model for actors as they can receive unauthorized invocations from linked capability providers. The problem has been patched in versions `0.52.2` and greater. There is no workaround and users are advised to upgrade to an unaffected version as soon as possible.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2022-23366

    Last Modified: 21 Nov 2024

    HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2022-23365

    Last Modified: 21 Nov 2024

    HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2022-23364

    Last Modified: 21 Nov 2024

    HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2022-23363

    Last Modified: 21 Nov 2024

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.

    Published: 21 Jan 2022
    7.5
    High

    CVE-2021-39480

    Last Modified: 21 Nov 2024

    Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46313

    Last Modified: 21 Nov 2024

    The binary MP4Box in GPAC v1.0.1 was discovered to contain a segmentation fault via the function __memmove_avx_unaligned_erms (). This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46311

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_destroy_routes () at scenegraph/vrml_route.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46240

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46239

    Last Modified: 21 Nov 2024

    The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at utils/alloc.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46238

    Last Modified: 21 Nov 2024

    GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegraph.c. This vulnerability can lead to a program crash, causing a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46237

    Last Modified: 21 Nov 2024

    An untrusted pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46236

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_vrml_field_pointer_del () at scenegraph/vrml_tools.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2021-46234

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    8.1
    High

    CVE-2022-22553

    Last Modified: 21 Nov 2024

    Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.

    Published: 21 Jan 2022
    6.9
    Medium

    CVE-2022-22552

    Last Modified: 21 Nov 2024

    Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.

    Published: 21 Jan 2022