CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2022-22551

    Last Modified: 21 Nov 2024

    DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.

    Published: 21 Jan 2022
    7.8
    High

    CVE-2021-36339

    Last Modified: 21 Nov 2024

    The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.

    Published: 21 Jan 2022
    6.3
    Medium

    CVE-2021-36338

    Last Modified: 21 Nov 2024

    Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.

    Published: 21 Jan 2022
    7.5
    High

    CVE-2021-23631

    Last Modified: 21 Nov 2024

    This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a converted PNG file.

    Published: 21 Jan 2022
    7.5
    High

    CVE-2021-23460

    Last Modified: 21 Nov 2024

    The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.

    Published: 21 Jan 2022
    8.6
    High

    CVE-2021-23664

    Last Modified: 21 Nov 2024

    The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-40595

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-40247

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.

    Published: 21 Jan 2022
    5.4
    Medium

    CVE-2021-33966

    Last Modified: 21 Nov 2024

    Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

    Published: 21 Jan 2022
    4.3
    Medium

    CVE-2021-40691

    Last Modified: 21 Nov 2024

    A session hijack risk was identified in the Shibboleth authentication plugin.

    Published: 21 Jan 2022
    4.3
    Medium

    CVE-2021-40695

    Last Modified: 21 Nov 2024

    It was possible for a student to view their quiz grade before it had been released, using a quiz web service.

    Published: 21 Jan 2022
    4.3
    Medium

    CVE-2021-40692

    Last Modified: 21 Nov 2024

    Insufficient capability checks made it possible for teachers to download users outside of their courses.

    Published: 21 Jan 2022
    6.5
    Medium

    CVE-2021-40693

    Last Modified: 21 Nov 2024

    An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

    Published: 21 Jan 2022
    7.3
    High

    CVE-2021-41835

    Last Modified: 16 Apr 2025

    Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an automated redirect from the unencrypted service on Port TCP/80 to the encrypted service.

    Published: 21 Jan 2022
    7.3
    High

    CVE-2021-43355

    Last Modified: 16 Apr 2025

    Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.

    Published: 21 Jan 2022
    5.4
    Medium

    CVE-2021-33848

    Last Modified: 16 Apr 2025

    Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scripting attacks. An attacker could inject JavaScript in a GET parameter of HTTP requests and perform unauthorized actions such as stealing internal information and performing actions in context of an authenticated user.

    Published: 21 Jan 2022
    6.3
    Medium

    CVE-2021-44464

    Last Modified: 16 Apr 2025

    Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software.

    Published: 21 Jan 2022
    5.3
    Medium

    CVE-2021-33843

    Last Modified: 16 Apr 2025

    Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.

    Published: 21 Jan 2022
    6.5
    Medium

    CVE-2021-31562

    Last Modified: 16 Apr 2025

    The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacker to compromise SSL/TLS sessions in different ways. An attacker may be able to eavesdrop on transferred data, manipulate data allegedly secured by SSL/TLS, and impersonate an entity to gain access to sensitive information.

    Published: 21 Jan 2022
    6.5
    Medium

    CVE-2021-23207

    Last Modified: 16 Apr 2025

    An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by impersonating users.

    Published: 21 Jan 2022
    5.3
    Medium

    CVE-2021-23195

    Last Modified: 16 Apr 2025

    Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled, all content of the directory will be displayed, allowing an attacker to identify and access files on the server.

    Published: 21 Jan 2022
    7.3
    High

    CVE-2021-23233

    Last Modified: 16 Apr 2025

    Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

    Published: 21 Jan 2022
    5.9
    Medium

    CVE-2021-33846

    Last Modified: 16 Apr 2025

    Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An attacker in possession of the key can issue valid JWTs and impersonate arbitrary users.

    Published: 21 Jan 2022
    7.3
    High

    CVE-2021-23196

    Last Modified: 16 Apr 2025

    The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.

    Published: 21 Jan 2022
    7.5
    High

    CVE-2021-23236

    Last Modified: 16 Apr 2025

    Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressing a button on the rack system.

    Published: 21 Jan 2022
    4.9
    Medium

    CVE-2021-40694

    Last Modified: 21 Nov 2024

    Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2022-23128

    Last Modified: 21 Nov 2024

    Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.95.3 to 10.97, ICONICS Hyper Historian versions 10.95.3 to 10.97, ICONICS AnalytiX versions 10.95.3 to 10.97 and ICONICS MobileHMI versions 10.95.3 to 10.97 allows a remote unauthenticated attacker to bypass the authentication of MC Works64, GENESIS64, Hyper Historian, AnalytiX and MobileHMI, and gain unauthorized access to the products, by sending specially crafted WebSocket packets to FrameWorX server, one of the functions of the products.

    Published: 21 Jan 2022
    6.1
    Medium

    CVE-2022-23127

    Last Modified: 21 Nov 2024

    Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS MobileHMI versions 10.96.2 and prior allows a remote unauthenticated attacker to gain authentication information of an MC Works64 or MobileHMI and perform any operation using the acquired authentication information, by injecting a malicious script in the URL of a monitoring screen delivered from the MC Works64 server or MobileHMI server to an application for mobile devices and leading a legitimate user to access this URL.

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2022-23129

    Last Modified: 21 Nov 2024

    Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS GENESIS64 versions 10.90 to 10.97 allows a local authenticated attacker to gain authentication information and to access the database illegally. This is because when configuration information of GridWorX, a database linkage function of GENESIS64 and MC Works64, is exported to a CSV file, the authentication information is saved in plaintext, and an attacker who can access this CSV file can gain the authentication information.

    Published: 21 Jan 2022
    6.1
    Medium

    CVE-2022-23728

    Last Modified: 21 Nov 2024

    Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.

    Published: 21 Jan 2022
    5.9
    Medium

    CVE-2022-23130

    Last Modified: 8 Jan 2026

    Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 and prior, Mitsubishi Electric GENESIS32 versions 9.7 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior allows an attacker to cause a DoS condition in the database server by getting a legitimate user to import a configuration file containing specially crafted stored procedures into GENESIS64, ICONICS Suite, MC Works64, or GENESIS32 and execute commands against the database from GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.

    Published: 21 Jan 2022
    8.1
    High

    CVE-2021-44593

    Last Modified: 21 Nov 2024

    Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.

    Published: 21 Jan 2022
    8.8
    High

    CVE-2022-0323

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

    Published: 21 Jan 2022
    4
    Medium

    CVE-2021-4016

    Last Modified: 21 Nov 2024

    Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to a loss of confidentiality. This issue was fixed in Rapid7 Insight Agent 3.1.3.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2020-4879

    Last Modified: 21 Nov 2024

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2020-4877

    Last Modified: 21 Nov 2024

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.

    Published: 21 Jan 2022
    8.2
    High

    CVE-2020-4876

    Last Modified: 21 Nov 2024

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.

    Published: 21 Jan 2022
    8.2
    High

    CVE-2020-4875

    Last Modified: 21 Nov 2024

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-46309

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-46308

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-46307

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-46201

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-35004

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0.1 Build 20200709 rel.66244(5553) wireless access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14656.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-35003

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14655.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-46200

    Last Modified: 27 Dec 2024

    An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-40855

    Last Modified: 21 Nov 2024

    The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in production.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2021-46198

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.

    Published: 21 Jan 2022
    7.5
    High

    CVE-2020-19858

    Last Modified: 21 Nov 2024

    Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.

    Published: 21 Jan 2022
    —
    Unknown

    CVE-2022-0329

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jan 2022
    6.7
    Medium

    CVE-2022-21933

    Last Modified: 21 Nov 2024

    ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.

    Published: 21 Jan 2022