CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-4142

    Last Modified: 21 Nov 2024

    The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.

    Published: 17 Jan 2022
    9.8
    Critical

    CVE-2021-4171

    Last Modified: 21 Nov 2024

    calibre-web is vulnerable to Business Logic Errors

    Published: 17 Jan 2022
    4.3
    Medium

    CVE-2022-0184

    Last Modified: 21 Nov 2024

    Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.

    Published: 17 Jan 2022
    4.6
    Medium

    CVE-2022-0183

    Last Modified: 21 Nov 2024

    Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware all versions allows an attacker who can physically access the device to obtain the stored passwords.

    Published: 17 Jan 2022
    5.4
    Medium

    CVE-2022-0182

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.

    Published: 17 Jan 2022
    6.1
    Medium

    CVE-2022-0181

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.

    Published: 17 Jan 2022
    8.8
    High

    CVE-2022-0180

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.

    Published: 17 Jan 2022
    3.3
    Low

    CVE-2022-0131

    Last Modified: 21 Nov 2024

    Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

    Published: 17 Jan 2022
    9.8
    Critical

    CVE-2022-0239

    Last Modified: 16 Apr 2026

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

    Published: 17 Jan 2022
    9.8
    Critical

    CVE-2022-23304

    Last Modified: 3 Nov 2025

    The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

    Published: 17 Jan 2022
    9.8
    Critical

    CVE-2022-23303

    Last Modified: 3 Nov 2025

    The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

    Published: 17 Jan 2022
    4.3
    Medium

    CVE-2021-25025

    Last Modified: 21 Nov 2024

    The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

    Published: 17 Jan 2022
    —
    Unknown

    CVE-2022-0259

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

    Published: 17 Jan 2022
    5.4
    Medium

    CVE-2021-4170

    Last Modified: 21 Nov 2024

    calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 16 Jan 2022
    4.3
    Medium

    CVE-2022-0238

    Last Modified: 21 Nov 2024

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 16 Jan 2022
    7.2
    High

    CVE-2021-33827

    Last Modified: 21 Nov 2024

    The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.

    Published: 15 Jan 2022
    8.8
    High

    CVE-2021-33828

    Last Modified: 21 Nov 2024

    The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.

    Published: 15 Jan 2022
    7.8
    High

    CVE-2021-44537

    Last Modified: 21 Nov 2024

    ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.

    Published: 15 Jan 2022
    5.4
    Medium

    CVE-2020-28919

    Last Modified: 21 Nov 2024

    A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.

    Published: 15 Jan 2022
    7.5
    High

    CVE-2021-42555

    Last Modified: 21 Nov 2024

    Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

    Published: 15 Jan 2022
    7.5
    High

    CVE-2021-35969

    Last Modified: 21 Nov 2024

    Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

    Published: 15 Jan 2022
    7.5
    High

    CVE-2021-33499

    Last Modified: 21 Nov 2024

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).

    Published: 15 Jan 2022
    7.5
    High

    CVE-2021-33498

    Last Modified: 21 Nov 2024

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).

    Published: 15 Jan 2022
    7.5
    High

    CVE-2021-32545

    Last Modified: 21 Nov 2024

    Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.

    Published: 15 Jan 2022
    9.8
    Critical

    CVE-2022-23178

    Last Modified: 21 Nov 2024

    An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.

    Published: 15 Jan 2022
    7.8
    High

    CVE-2022-23095

    Last Modified: 5 May 2025

    Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 15 Jan 2022
    7.8
    High

    CVE-2021-44049

    Last Modified: 21 Nov 2024

    CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.

    Published: 15 Jan 2022
    9.8
    Critical

    CVE-2021-33963

    Last Modified: 21 Nov 2024

    China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

    Published: 15 Jan 2022
    9.8
    Critical

    CVE-2021-24044

    Last Modified: 21 Nov 2024

    By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.

    Published: 15 Jan 2022
    9.8
    Critical

    CVE-2022-0839

    Last Modified: 3 Nov 2025

    Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

    Published: 15 Jan 2022
    4
    Medium

    CVE-2021-23566

    Last Modified: 3 Nov 2025

    The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-46171

    Last Modified: 21 Nov 2024

    Modex v2.11 was discovered to contain a NULL pointer dereference in set_create_id() at xtract.c.

    Published: 14 Jan 2022
    7.5
    High

    CVE-2021-46170

    Last Modified: 21 Nov 2024

    An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file.

    Published: 14 Jan 2022
    7.5
    High

    CVE-2021-23567

    Last Modified: 21 Nov 2024

    The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in the americanFlag module. Unfortunately this appears to have been a purposeful attempt by a maintainer of colors to make the package unusable, other maintainers' controls over this package appear to have been revoked in an attempt to prevent them from fixing the issue. Vulnerable Code js for (let i = 666; i < Infinity; i++;) { Alternative Remediation Suggested * Pin dependancy to 1.4.0

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-46169

    Last Modified: 21 Nov 2024

    Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache.

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-46168

    Last Modified: 21 Nov 2024

    Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-46021

    Last Modified: 21 Nov 2024

    An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

    Published: 14 Jan 2022
    7.5
    High

    CVE-2021-46020

    Last Modified: 21 Nov 2024

    An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.

    Published: 14 Jan 2022
    —
    Unknown

    CVE-2021-45782

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jan 2022
    —
    Unknown

    CVE-2021-45781

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jan 2022
    —
    Unknown

    CVE-2021-45780

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-44828

    Last Modified: 21 Nov 2024

    Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root privileges, corrupt memory, and modify the memory of other processes.

    Published: 14 Jan 2022
    8.8
    High

    CVE-2021-45406

    Last Modified: 21 Nov 2024

    In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.

    Published: 14 Jan 2022
    —
    Unknown

    CVE-2021-45779

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jan 2022
    9.8
    Critical

    CVE-2021-44530

    Last Modified: 21 Nov 2024

    An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.

    Published: 14 Jan 2022
    —
    Unknown

    CVE-2021-45778

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jan 2022
    —
    Unknown

    CVE-2021-45775

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jan 2022
    —
    Unknown

    CVE-2021-45774

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Jan 2022
    7.5
    High

    CVE-2021-3965

    Last Modified: 21 Nov 2024

    Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.

    Published: 14 Jan 2022
    4.8
    Medium

    CVE-2021-36920

    Last Modified: 20 Feb 2025

    Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).

    Published: 14 Jan 2022