CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2021-44564

    Last Modified: 21 Nov 2024

    A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and knowledge of its IP address. The attack exploits the unsecured communication channel used between the administration tool Easyconnect and the SYNC device (in the affected family of SYNC products).

    Published: 6 Jan 2022
    7.5
    High

    CVE-2021-44351

    Last Modified: 21 Nov 2024

    An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.

    Published: 6 Jan 2022
    6.1
    Medium

    CVE-2021-36739

    Last Modified: 22 May 2025

    The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.

    Published: 6 Jan 2022
    6.1
    Medium

    CVE-2021-36738

    Last Modified: 21 Nov 2024

    The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact

    Published: 6 Jan 2022
    6.1
    Medium

    CVE-2021-36737

    Last Modified: 21 Nov 2024

    The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact

    Published: 6 Jan 2022
    5.9
    Medium

    CVE-2022-22707

    Last Modified: 21 Nov 2024

    In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 32-bit system is much more likely to be affected than a 64-bit system.

    Published: 6 Jan 2022
    5.3
    Medium

    CVE-2021-46145

    Last Modified: 21 Nov 2024

    The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization.

    Published: 6 Jan 2022
    6.1
    Medium

    CVE-2022-0122

    Last Modified: 21 Nov 2024

    forge is vulnerable to URL Redirection to Untrusted Site

    Published: 6 Jan 2022
    9.8
    Critical

    CVE-2022-22704

    Last Modified: 21 Nov 2024

    The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

    Published: 6 Jan 2022
    6.1
    Medium

    CVE-2021-46144

    Last Modified: 21 Nov 2024

    Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

    Published: 6 Jan 2022
    8.1
    High

    CVE-2021-46143

    Last Modified: 5 May 2025

    In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

    Published: 6 Jan 2022
    8
    High

    CVE-2022-0121

    Last Modified: 24 Feb 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.

    Published: 6 Jan 2022
    7.2
    High

    CVE-2021-43947

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

    Published: 6 Jan 2022
    3
    Low

    CVE-2021-25743

    Last Modified: 13 Jan 2026

    kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

    Published: 6 Jan 2022
    5.5
    Medium

    CVE-2021-46044

    Last Modified: 21 Nov 2024

    A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1via ShiftMetaOffset.isra, which causes a Denial of Service (context-dependent).

    Published: 6 Jan 2022
    5.5
    Medium

    CVE-2023-23002

    Last Modified: 20 Mar 2025

    In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

    Published: 6 Jan 2022
    5.5
    Medium

    CVE-2021-46039

    Last Modified: 21 Nov 2024

    A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offsets.part function, which causes a Denial of Service (context-dependent).

    Published: 6 Jan 2022
    5.5
    Medium

    CVE-2021-46040

    Last Modified: 21 Nov 2024

    A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the finplace_shift_moov_meta_offsets function, which causes a Denial of Servie (context-dependent).

    Published: 6 Jan 2022
    5.5
    Medium

    CVE-2021-46041

    Last Modified: 21 Nov 2024

    A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new function, which causes a Denial of Service.

    Published: 6 Jan 2022
    5.5
    Medium

    CVE-2021-46042

    Last Modified: 21 Nov 2024

    A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the _fseeko function, which causes a Denial of Service.

    Published: 6 Jan 2022
    5.5
    Medium

    CVE-2021-46043

    Last Modified: 21 Nov 2024

    A Pointer Dereference Vulnerability exits in GPAC 1.0.1 in the gf_list_count function, which causes a Denial of Service.

    Published: 6 Jan 2022
    7.8
    High

    CVE-2022-0128

    Last Modified: 21 Nov 2024

    vim is vulnerable to Out-of-bounds Read

    Published: 6 Jan 2022
    7.5
    High

    CVE-2021-22569

    Last Modified: 21 Apr 2025

    An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.

    Published: 6 Jan 2022
    7.5
    High

    CVE-2021-43045

    Last Modified: 21 Nov 2024

    A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.

    Published: 6 Jan 2022
    6.1
    Medium

    CVE-2020-27428

    Last Modified: 21 Nov 2024

    A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted sb3 file.

    Published: 5 Jan 2022
    6.1
    Medium

    CVE-2020-23986

    Last Modified: 21 Nov 2024

    Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError.

    Published: 5 Jan 2022
    8.2
    High

    CVE-2021-45971

    Last Modified: 11 Aug 2026

    An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (CommBufferData).

    Published: 5 Jan 2022
    9.8
    Critical

    CVE-2021-41842

    Last Modified: 21 Nov 2024

    An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check.

    Published: 5 Jan 2022
    8.2
    High

    CVE-2021-45969

    Last Modified: 11 Aug 2026

    An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the CommBuffer+8 location).

    Published: 5 Jan 2022
    8.2
    High

    CVE-2021-45970

    Last Modified: 11 Aug 2026

    An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the status code saved at the CommBuffer+4 location).

    Published: 5 Jan 2022
    7.5
    High

    CVE-2020-5956

    Last Modified: 21 Nov 2024

    An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer.

    Published: 5 Jan 2022
    5.9
    Medium

    CVE-2022-21653

    Last Modified: 22 Apr 2025

    Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.

    Published: 5 Jan 2022
    3.5
    Low

    CVE-2022-21652

    Last Modified: 23 Apr 2025

    Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user session in the event of a password change. With version 5.7.7 the session validation was adjusted, so that sessions created prior to the latest password change of a customer account can't be used to login with said account. This also means, that upon a password change, all existing sessions for a given customer account are automatically considered invalid. There is no workaround for this issue.

    Published: 5 Jan 2022
    6.8
    Medium

    CVE-2022-21651

    Last Modified: 23 Apr 2025

    Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There is no workaround and users are advised to upgrade as soon as possible.

    Published: 5 Jan 2022
    4.3
    Medium

    CVE-2022-21642

    Last Modified: 23 Apr 2025

    Discourse is an open source platform for community discussion. In affected versions when composing a message from topic the composer user suggestions reveals whisper participants. The issue has been patched in stable version 2.7.13 and beta version 2.8.0.beta11. There is no workaround for this issue and users are advised to upgrade.

    Published: 5 Jan 2022
    9.9
    Critical

    CVE-2021-43779

    Last Modified: 8 Sept 2025

    GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.

    Published: 5 Jan 2022
    7.5
    High

    CVE-2021-38918

    Last Modified: 21 Nov 2024

    IBM PowerVM Hypervisor FW860, FW940, FW950, and FW1010, through a specific sequence of VM management operations could lead to a violation of the isolation between peer VMs. IBM X-Force ID: 210019.

    Published: 5 Jan 2022
    8.8
    High

    CVE-2022-22111

    Last Modified: 21 Nov 2024

    In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.

    Published: 5 Jan 2022
    7.5
    High

    CVE-2022-22110

    Last Modified: 21 Nov 2024

    In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.

    Published: 5 Jan 2022
    5.4
    Medium

    CVE-2022-22109

    Last Modified: 21 Nov 2024

    In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victim’s browser when they open the “/tasks” page to view all the tasks.

    Published: 5 Jan 2022
    4.3
    Medium

    CVE-2022-22108

    Last Modified: 21 Nov 2024

    In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.

    Published: 5 Jan 2022
    4.3
    Medium

    CVE-2022-22107

    Last Modified: 21 Nov 2024

    In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this type of user is not authorized to view the calendar at all.

    Published: 5 Jan 2022
    6.7
    Medium

    CVE-2021-4178

    Last Modified: 21 Nov 2024

    A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

    Published: 5 Jan 2022
    5.3
    Medium

    CVE-2020-15933

    Last Modified: 21 Nov 2024

    A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via client-side resources inspection.

    Published: 5 Jan 2022
    6.1
    Medium

    CVE-2021-31589

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

    Published: 5 Jan 2022
    4.6
    Medium

    CVE-2021-22567

    Last Modified: 21 Apr 2025

    Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.

    Published: 5 Jan 2022
    6.5
    Medium

    CVE-2021-43946

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.13.21, and from version 8.14.0 before 8.20.9.

    Published: 5 Jan 2022
    5.5
    Medium

    CVE-2021-45832

    Last Modified: 21 Nov 2024

    A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (context-dependent).

    Published: 5 Jan 2022
    5.5
    Medium

    CVE-2021-45830

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.

    Published: 5 Jan 2022
    5.5
    Medium

    CVE-2021-45831

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Service.

    Published: 5 Jan 2022