CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2021-40003

    Last Modified: 21 Nov 2024

    HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

    Published: 7 Jan 2022
    8.8
    High

    CVE-2021-40002

    Last Modified: 21 Nov 2024

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

    Published: 7 Jan 2022
    5.3
    Medium

    CVE-2021-40001

    Last Modified: 21 Nov 2024

    The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTime application to be unavailable.

    Published: 7 Jan 2022
    8.8
    High

    CVE-2021-40000

    Last Modified: 21 Nov 2024

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

    Published: 7 Jan 2022
    4.2
    Medium

    CVE-2021-40041

    Last Modified: 21 Nov 2024

    There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability by injecting special characters. Successful exploit could cause certain information disclosure. Affected product versions include: WS318n-21 10.0.2.2, 10.0.2.5 and 10.0.2.6.

    Published: 7 Jan 2022
    5.3
    Medium

    CVE-2022-22289

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2022-22288

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.

    Published: 7 Jan 2022
    3.9
    Low

    CVE-2022-22287

    Last Modified: 21 Nov 2024

    Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.

    Published: 7 Jan 2022
    4.4
    Medium

    CVE-2022-22286

    Last Modified: 21 Nov 2024

    A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent.

    Published: 7 Jan 2022
    4.4
    Medium

    CVE-2022-22285

    Last Modified: 21 Nov 2024

    A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent.

    Published: 7 Jan 2022
    2.8
    Low

    CVE-2022-22283

    Last Modified: 21 Nov 2024

    Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.

    Published: 7 Jan 2022
    5.7
    Medium

    CVE-2022-22284

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2022-22271

    Last Modified: 21 Nov 2024

    A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy data from arbitrary memory.

    Published: 7 Jan 2022
    4.4
    Medium

    CVE-2022-22270

    Last Modified: 21 Nov 2024

    An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.

    Published: 7 Jan 2022
    4
    Medium

    CVE-2022-22269

    Last Modified: 21 Nov 2024

    Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.

    Published: 7 Jan 2022
    4
    Medium

    CVE-2022-22267

    Last Modified: 21 Nov 2024

    Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.

    Published: 7 Jan 2022
    4
    Medium

    CVE-2022-22272

    Last Modified: 21 Nov 2024

    Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission

    Published: 7 Jan 2022
    6.1
    Medium

    CVE-2022-22268

    Last Modified: 21 Nov 2024

    Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.

    Published: 7 Jan 2022
    7.7
    High

    CVE-2022-22264

    Last Modified: 21 Nov 2024

    Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.

    Published: 7 Jan 2022
    4
    Medium

    CVE-2022-22266

    Last Modified: 21 Nov 2024

    (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.

    Published: 7 Jan 2022
    4
    Medium

    CVE-2022-22263

    Last Modified: 21 Nov 2024

    Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.

    Published: 7 Jan 2022
    5
    Medium

    CVE-2022-22265

    Last Modified: 30 Oct 2025

    An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

    Published: 7 Jan 2022
    7.4
    High

    CVE-2021-32998

    Last Modified: 17 Apr 2025

    The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. INIT START/restore from backup required.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-32996

    Last Modified: 17 Apr 2025

    The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash. A restart is required.

    Published: 7 Jan 2022
    —
    Unknown

    CVE-2021-46058

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2021-46055

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2021-46054

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2021-46053

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Binaryen 103. The program terminates with signal SIGKILL.

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2021-46052

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::Tuple::validate.

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2021-46050

    Last Modified: 21 Nov 2024

    A Stack Overflow vulnerability exists in Binaryen 103 via the printf_common function.

    Published: 7 Jan 2022
    5.5
    Medium

    CVE-2021-46048

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::readFunctions.

    Published: 7 Jan 2022
    4.3
    Medium

    CVE-2022-22702

    Last Modified: 21 Nov 2024

    PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user to carry out SSRF attacks and port enumeration.

    Published: 7 Jan 2022
    6.5
    Medium

    CVE-2022-22701

    Last Modified: 21 Nov 2024

    PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

    Published: 7 Jan 2022
    9.8
    Critical

    CVE-2021-23543

    Last Modified: 21 Nov 2024

    All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.

    Published: 7 Jan 2022
    7.3
    High

    CVE-2021-23568

    Last Modified: 21 Nov 2024

    The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

    Published: 7 Jan 2022
    9.8
    Critical

    CVE-2021-23594

    Last Modified: 21 Nov 2024

    All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.

    Published: 7 Jan 2022
    5.3
    Medium

    CVE-2021-42748

    Last Modified: 21 Nov 2024

    In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API.

    Published: 7 Jan 2022
    5.3
    Medium

    CVE-2021-42749

    Last Modified: 21 Nov 2024

    In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt field is not set.

    Published: 7 Jan 2022
    7.8
    High

    CVE-2021-38990

    Last Modified: 21 Nov 2024

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-38957

    Last Modified: 21 Nov 2024

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.

    Published: 7 Jan 2022
    5.3
    Medium

    CVE-2021-38956

    Last Modified: 21 Nov 2024

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system. IBM X-Force ID: 212038

    Published: 7 Jan 2022
    7.5
    High

    CVE-2021-38921

    Last Modified: 21 Nov 2024

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.

    Published: 7 Jan 2022
    5.4
    Medium

    CVE-2021-38895

    Last Modified: 21 Nov 2024

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209563.

    Published: 7 Jan 2022
    2.7
    Low

    CVE-2021-38894

    Last Modified: 21 Nov 2024

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 209515.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2022-21667

    Last Modified: 23 Apr 2025

    soketi is an open-source WebSockets server. There is an unhandled case when reading POST requests which results in the server crashing if it could not read the body of a request. In the event that a POST request is sent to any endpoint of the server with an empty body, even unauthenticated with the Pusher Protocol, it will crash the server. All users that run the server are affected by this vulnerability and it's highly recommended to upgrade to the latest patch. There are no workarounds for this issue.

    Published: 7 Jan 2022
    7.5
    High

    CVE-2022-0133

    Last Modified: 21 Nov 2024

    peertube is vulnerable to Improper Access Control

    Published: 7 Jan 2022
    7.5
    High

    CVE-2022-0132

    Last Modified: 21 Nov 2024

    peertube is vulnerable to Server-Side Request Forgery (SSRF)

    Published: 7 Jan 2022
    7.5
    High

    CVE-2020-29050

    Last Modified: 21 Nov 2024

    SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.

    Published: 7 Jan 2022
    8.8
    High

    CVE-2021-46147

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.

    Published: 7 Jan 2022
    6.5
    Medium

    CVE-2021-46148

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential information (e.g., IP addresses and User-Agent headers for election traffic) on a testwiki SecurePoll instance.

    Published: 7 Jan 2022