7.5
    High

    CVE-2022-0725

    Last Modified: 21 Nov 2024

    A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

    Published:7 Mar 2022
    7.5
    High

    CVE-2022-0666

    Last Modified: 21 Nov 2024

    CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist microweber/microweber prior to 1.2.11.

    Published:18 Feb 2022
    9.1
    Critical

    CVE-2022-0591

    Last Modified: 21 Nov 2024

    The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

    Published:21 Mar 2022
    7.2
    High

    CVE-2022-0557

    Last Modified: 21 Feb 2022

    OS Command Injection in Packagist microweber/microweber prior to 1.2.11.

    Source:Chetanya Sharma
    Published:11 Feb 2022
    10
    Critical

    CVE-2022-0543

    Last Modified: 10 Nov 2025

    It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

    Published:18 Feb 2022
    9.8
    Critical

    CVE-2022-0540

    Last Modified: 21 Nov 2024

    A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.

    Published:20 Apr 2022
    5.5
    Medium

    CVE-2022-0529

    Last Modified: 13 Feb 2025

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

    Published:24 Jan 2022
    7.8
    High

    CVE-2022-0492

    Last Modified: 3 Jun 2026

    A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

    Published:7 Feb 2022
    4.4
    Medium

    CVE-2022-0486

    Last Modified: 21 Nov 2024

    Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

    Published:17 May 2022
    9.1
    Critical

    CVE-2022-0482

    Last Modified: 19 Apr 2022

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

    Source:Alexandre ZANNI
    Published:9 Mar 2022
    4.8
    Medium

    CVE-2022-0448

    Last Modified: 8 Feb 2022

    The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

    Source:Shweta Mahajan
    Published:7 Mar 2022
    9.8
    Critical

    CVE-2022-0441

    Last Modified: 18 Feb 2022

    The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

    Source:numan türle
    Published:7 Mar 2022
    8.8
    High

    CVE-2022-0439

    Last Modified: 21 Nov 2024

    The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

    Published:7 Mar 2022
    8.8
    High

    CVE-2022-0435

    Last Modified: 21 Nov 2024

    A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.

    Published:10 Feb 2022
    4.3
    Medium

    CVE-2022-0377

    Last Modified: 2 Feb 2022

    Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of this request, the name of the user-supplied image is changed with a MD5 value. This process can be conducted only when type of the image is JPG or PNG. An attacker can use this vulnerability in order to rename an arbitrary image file. By doing this, they could destroy the design of the web site.

    Source:Ceylan BOZOĞULLARINDAN
    Published:28 Feb 2022
    6.5
    Medium

    CVE-2022-0337

    Last Modified: 21 Nov 2024

    Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. (Chrome security severity: High)

    Published:2 Jan 2023
    9.8
    Critical

    CVE-2022-0332

    Last Modified: 2 Feb 2022

    A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

    Source:lavclash75
    Published:25 Jan 2022
    8.1
    High

    CVE-2022-0324

    Last Modified: 30 Apr 2025

    There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that could cause buffer overflow in a memcpy call, leading to out-of-bounds memory write that would cause dhcp6relay to crash. Dhcp6relay is a critical process and could cause dhcp relay docker to shutdown. Discovered by Eugene Lim of GovTech Singapore.

    Published:14 Nov 2022
    9.8
    Critical

    CVE-2022-0316

    Last Modified: 3 Apr 2025

    The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

    Published:23 Jan 2023
    9.8
    Critical

    CVE-2022-0265

    Last Modified: 21 Nov 2024

    Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

    Published:3 Mar 2022
    7.5
    High

    CVE-2022-0236

    Last Modified: 31 Jan 2025

    The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

    Published:18 Jan 2022
    5.5
    Medium

    CVE-2022-0219

    Last Modified: 21 Nov 2024

    Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2.

    Published:20 Jan 2022
    8.4
    High

    CVE-2022-0185

    Last Modified: 6 Nov 2025

    A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

    Published:18 Jan 2022
    9.8
    Critical

    CVE-2022-0169

    Last Modified: 21 Nov 2024

    The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

    Published:14 Mar 2022
    6.1
    Medium

    CVE-2022-0165

    Last Modified: 21 Nov 2024

    The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated users

    Published:14 Mar 2022
    6.5
    Medium

    CVE-2022-0155

    Last Modified: 21 Nov 2024

    follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

    Published:10 Jan 2022
    7.4
    High

    CVE-2022-0088

    Last Modified: 2 Dec 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.

    Source:CodeSecLab
    Published:3 Apr 2022
    Unknown

    CVE-2022-26

    https://github.com/kullai-secasure/CVE-2022-26xx9

    6.8
    Medium

    CVE-2022-0020

    Last Modified: 8 Apr 2023

    A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.

    Source:omurugur
    Published:10 Feb 2022
    6.5
    Medium

    CVE-2022-0001

    Last Modified: 5 May 2025

    Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

    Published:8 Mar 2022
    Unknown

    CVE-2021-268855

    https://github.com/sikkertech/CVE-2021-268855

    Unknown

    CVE-2021-56789

    https://github.com/DataSurgeon-ds/ds-cve-plugin

    6.7
    Medium

    CVE-2021-47881

    Last Modified: 15 Apr 2026

    dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to overwrite memory by manipulating the milstd1553result.txt file. Attackers can craft a malicious file with carefully constructed payload and alignment sections to potentially execute arbitrary code on the Windows system.

    Published:23 Jan 2026
    9.8
    Critical

    CVE-2021-46704

    Last Modified: 21 Nov 2024

    In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.

    Published:6 Mar 2022
    9.8
    Critical

    CVE-2021-46703

    Last Modified: 21 Nov 2024

    In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published:6 Mar 2022
    5.5
    Medium

    CVE-2021-46702

    Last Modified: 21 Nov 2024

    Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. This can be accomplished by analyzing RAM memory even several hours after the local user used the product. This occurs because the product doesn't properly free memory.

    Published:26 Feb 2022
    9.1
    Critical

    CVE-2021-46424

    Last Modified: 12 May 2022

    Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

    Source:Ahmed Alroky
    Published:27 Apr 2022
    9.8
    Critical

    CVE-2021-46422

    Last Modified: 17 May 2022

    Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

    Source:Ahmed Alroky
    Published:27 Apr 2022
    9.1
    Critical

    CVE-2021-46419

    Last Modified: 11 Apr 2022

    An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

    Source:Momen Eldawakhly
    Published:7 Apr 2022
    7.5
    High

    CVE-2021-46418

    Last Modified: 11 Apr 2022

    An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

    Source:Momen Eldawakhly
    Published:7 Apr 2022
    7.5
    High

    CVE-2021-46417

    Last Modified: 11 Apr 2022

    Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.

    Source:Momen Eldawakhly
    Published:7 Apr 2022
    5.4
    Medium

    CVE-2021-46416

    Last Modified: 11 Apr 2022

    Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

    Source:Momen Eldawakhly
    Published:7 Apr 2022
    8.8
    High

    CVE-2021-46398

    Last Modified: 8 Feb 2022

    A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.

    Source:FEBIN MON SAJI
    Published:4 Feb 2022
    6.1
    Medium

    CVE-2021-46387

    Last Modified: 2 Mar 2022

    ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.

    Source:Momen Eldawakhly
    Published:1 Mar 2022
    7.5
    High

    CVE-2021-46381

    Last Modified: 11 May 2022

    Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

    Source:Momen Eldawakhly
    Published:4 Mar 2022
    6.1
    Medium

    CVE-2021-46379

    Last Modified: 11 May 2022

    DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

    Source:Ahmed Alroky
    Published:4 Mar 2022
    7.5
    High

    CVE-2021-46378

    Last Modified: 11 May 2022

    DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.

    Source:Ahmed Alroky
    Published:4 Mar 2022
    8.8
    High

    CVE-2021-46366

    Last Modified: 21 Nov 2024

    An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

    Published:11 Feb 2022
    7.8
    High

    CVE-2021-46365

    Last Modified: 21 Nov 2024

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

    Published:11 Feb 2022
    7.8
    High

    CVE-2021-46364

    Last Modified: 21 Nov 2024

    A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

    Published:11 Feb 2022