CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-46329

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2021-46326

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2021-46325

    Last Modified: 21 Nov 2024

    Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2021-46324

    Last Modified: 21 Nov 2024

    Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46323

    Last Modified: 21 Nov 2024

    Espruino 2v11.251 was discovered to contain a SEGV vulnerability via src/jsinteractive.c in jsiGetDeviceFromClass.

    Published: 20 Jan 2022
    5.9
    Medium

    CVE-2021-29785

    Last Modified: 21 Nov 2024

    IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 203169.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-46061

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44090

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44245

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44244

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2022-23120

    Last Modified: 21 Nov 2024

    A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.

    Published: 20 Jan 2022
    7.5
    High

    CVE-2022-23119

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44092

    Last Modified: 15 Jan 2025

    An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.

    Published: 20 Jan 2022
    5.4
    Medium

    CVE-2021-44091

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2022-0219

    Last Modified: 21 Nov 2024

    Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2.

    Published: 20 Jan 2022
    6.1
    Medium

    CVE-2021-44829

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44734

    Last Modified: 21 Nov 2024

    Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44736

    Last Modified: 21 Nov 2024

    The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44735

    Last Modified: 21 Nov 2024

    Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

    Published: 20 Jan 2022
    8.8
    High

    CVE-2021-44737

    Last Modified: 21 Nov 2024

    PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2021-44738

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.

    Published: 20 Jan 2022
    5.4
    Medium

    CVE-2022-0285

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-32039

    Last Modified: 21 Nov 2024

    Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2022-22820

    Last Modified: 21 Nov 2024

    Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-34600

    Last Modified: 21 Nov 2024

    Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.

    Published: 20 Jan 2022
    4.3
    Medium

    CVE-2022-0282

    Last Modified: 24 Feb 2026

    Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.

    Published: 20 Jan 2022
    7.5
    High

    CVE-2022-0281

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

    Published: 20 Jan 2022
    5.4
    Medium

    CVE-2021-3866

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.

    Published: 20 Jan 2022
    6.5
    Medium

    CVE-2022-22733

    Last Modified: 21 Nov 2024

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.

    Published: 20 Jan 2022
    6.5
    Medium

    CVE-2021-45230

    Last Modified: 21 Nov 2024

    In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.

    Published: 20 Jan 2022
    5.4
    Medium

    CVE-2022-0278

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

    Published: 20 Jan 2022
    8.8
    High

    CVE-2021-43269

    Last Modified: 21 Nov 2024

    In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)

    Published: 20 Jan 2022
    6.5
    Medium

    CVE-2022-0277

    Last Modified: 21 Nov 2024

    Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

    Published: 20 Jan 2022
    7.3
    High

    CVE-2022-21658

    Last Modified: 22 Apr 2025

    Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don't have usable APIs to properly mitigate the attack, and are thus still vulnerable even with a patched toolchain: macOS before version 10.10 (Yosemite) and REDOX. We recommend everyone to update to Rust 1.58.1 as soon as possible, especially people developing programs expected to run in privileged contexts (including system daemons and setuid binaries), as those have the highest risk of being affected by this. Note that adding checks in your codebase before calling remove_dir_all will not mitigate the vulnerability, as they would also be vulnerable to race conditions like remove_dir_all itself. The existing mitigation is working as intended outside of race conditions.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2021-45417

    Last Modified: 21 Nov 2024

    AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46322

    Last Modified: 21 Nov 2024

    Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack.c.

    Published: 20 Jan 2022
    4.3
    Medium

    CVE-2021-46028

    Last Modified: 21 Nov 2024

    In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.

    Published: 19 Jan 2022
    5.4
    Medium

    CVE-2021-46026

    Last Modified: 10 Apr 2025

    mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag in the background blog management.

    Published: 19 Jan 2022
    6.5
    Medium

    CVE-2021-46027

    Last Modified: 22 Apr 2025

    mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added

    Published: 19 Jan 2022
    5.4
    Medium

    CVE-2021-46025

    Last Modified: 21 Nov 2024

    A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.

    Published: 19 Jan 2022
    6.1
    Medium

    CVE-2021-4143

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.

    Published: 19 Jan 2022
    8.2
    High

    CVE-2022-21699

    Last Modified: 22 Apr 2025

    IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

    Published: 19 Jan 2022
    5.4
    Medium

    CVE-2021-44777

    Last Modified: 20 Feb 2025

    Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6).

    Published: 19 Jan 2022
    4.8
    Medium

    CVE-2022-23045

    Last Modified: 21 Nov 2024

    PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.

    Published: 19 Jan 2022
    7.2
    High

    CVE-2022-23046

    Last Modified: 21 Nov 2024

    PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

    Published: 19 Jan 2022
    8.8
    High

    CVE-2021-23843

    Last Modified: 21 Nov 2024

    The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to configuration data on the device. An attacker can exploit this vulnerability to manipulate the device\'s configuration or make it unresponsive in the local network. The attacker needs to have access to the local network, typically even the same subnet.

    Published: 19 Jan 2022
    5.7
    Medium

    CVE-2021-23842

    Last Modified: 21 Nov 2024

    Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network traffic, decrypt and further investigate the device\'s firmware file, and change the device configuration. The attacker needs to have access to the local network, typically even the same subnet.

    Published: 19 Jan 2022
    6.1
    Medium

    CVE-2021-26247

    Last Modified: 21 Nov 2024

    As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.

    Published: 19 Jan 2022
    5.4
    Medium

    CVE-2021-23225

    Last Modified: 21 Nov 2024

    Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.

    Published: 19 Jan 2022
    5.4
    Medium

    CVE-2021-3816

    Last Modified: 21 Nov 2024

    Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.

    Published: 19 Jan 2022