| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23640 | Cri | 0.57 | 9.8 | 0.01 | Mar 2, 2022 | Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a… | ||
| CVE-2022-23878 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. | ||
| CVE-2022-25016 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-24306 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. | ||
| CVE-2022-24305 | Cri | 0.64 | 9.8 | 0.03 | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation. | ||
| CVE-2022-25010 | Cri | 0.00 | 9.1 | 0.01 | Mar 1, 2022 | The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system. | ||
| CVE-2022-24720 | Cri | 0.57 | 9.8 | 0.03 | Mar 1, 2022 | image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell… | ||
| CVE-2021-41193 | Cri | 0.57 | 9.8 | 0.02 | Mar 1, 2022 | wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs… | ||
| CVE-2021-36166 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2022 | An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties. | ||
| CVE-2021-4039 | Cri | 0.72 | 9.8 | 0.71 | Mar 1, 2022 | A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device. | ||
| CVE-2021-42767 | — | Cri | 0.59 | 9.1 | 0.02 | Mar 1, 2022 | A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1. | |
| CVE-2020-12775 | Cri | 0.64 | 9.8 | 0.03 | Mar 1, 2022 | Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt… | ||
| CVE-2022-25411 | Cri | 0.64 | 9.8 | 0.03 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-45414 | Cri | 0.64 | 9.8 | 0.04 | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver. | ||
| CVE-2022-24711 | Cri | 0.54 | 9.4 | 0.01 | Feb 28, 2022 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for… | ||
| CVE-2021-43086 | Cri | 0.64 | 9.8 | 0.01 | Feb 28, 2022 | ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in… | ||
| CVE-2022-24571 | — | Cri | 0.64 | 9.8 | 0.02 | Feb 28, 2022 | Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. | |
| CVE-2022-0768 | — | Cri | 0.52 | 9.1 | 0.02 | Feb 28, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2. | |
| CVE-2022-0412 | Cri | 0.70 | 9.8 | 0.74 | Feb 28, 2022 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated… | ||
| CVE-2021-25010 | Cri | 0.62 | 9.6 | 0.01 | Feb 28, 2022 | The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting… | ||
| CVE-2022-25359 | Cri | 0.65 | 9.1 | 0.37 | Feb 26, 2022 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | ||
| CVE-2022-25096 | Cri | 0.64 | 9.8 | 0.02 | Feb 26, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php. | ||
| CVE-2022-25095 | Cri | 0.64 | 9.8 | 0.01 | Feb 26, 2022 | Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request. | ||
| CVE-2022-25263 | Cri | 0.64 | 9.8 | 0.02 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. | ||
| CVE-2022-25262 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains Hub before 2022.1.14434, SAML request takeover was possible. | ||
| CVE-2022-25260 | Cri | 0.59 | 9.1 | 0.02 | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF). | ||
| CVE-2022-25064 | Cri | 0.67 | 9.8 | 0.36 | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. | ||
| CVE-2022-25061 | Cri | 0.69 | 9.8 | 0.67 | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. | ||
| CVE-2022-25060 | Cri | 0.68 | 9.8 | 0.48 | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. | ||
| CVE-2022-24442 | Cri | 0.64 | 9.8 | 0.04 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | ||
| CVE-2021-42952 | Cri | 0.64 | 9.9 | 0.02 | Feb 25, 2022 | Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata… | ||
| CVE-2021-40046 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege. | ||
| CVE-2021-22480 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow. | ||
| CVE-2021-22448 | Cri | 0.59 | 9.1 | 0.01 | Feb 25, 2022 | There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files. | ||
| CVE-2021-22434 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22433 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22432 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2021-22431 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access. | ||
| CVE-2021-22430 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection. | ||
| CVE-2021-22429 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22426 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed. | ||
| CVE-2021-22394 | Cri | 0.59 | 9.1 | 0.01 | Feb 25, 2022 | There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration. | ||
| CVE-2022-24340 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. | ||
| CVE-2022-24331 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. | ||
| CVE-2021-45977 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2022 | JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm… | ||
| CVE-2021-39363 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved. | ||
| CVE-2022-25149 | Cri | 0.70 | 9.8 | 0.78 | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to… | ||
| CVE-2022-25148 | Cri | 0.73 | 9.8 | 0.81 | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL… | ||
| CVE-2022-25004 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php. | ||
| CVE-2022-25003 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php. |
- risk 0.57cvss 9.8epss 0.01
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a…
- risk 0.64cvss 9.8epss 0.02
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
- risk 0.64cvss 9.8epss 0.02
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
- risk 0.00cvss 9.1epss 0.01
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
- risk 0.57cvss 9.8epss 0.03
image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell…
- risk 0.57cvss 9.8epss 0.02
wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs…
- risk 0.64cvss 9.8epss 0.01
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
- risk 0.72cvss 9.8epss 0.71
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
- risk 0.59cvss 9.1epss 0.02
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.
- risk 0.64cvss 9.8epss 0.03
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt…
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.04
A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.
- risk 0.54cvss 9.4epss 0.01
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for…
- risk 0.64cvss 9.8epss 0.01
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in…
- risk 0.64cvss 9.8epss 0.02
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
- risk 0.52cvss 9.1epss 0.02
Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
- risk 0.70cvss 9.8epss 0.74
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated…
- risk 0.62cvss 9.6epss 0.01
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting…
- risk 0.65cvss 9.1epss 0.37
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
- risk 0.64cvss 9.8epss 0.02
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.
- risk 0.64cvss 9.8epss 0.02
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
- risk 0.64cvss 9.8epss 0.01
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
- risk 0.59cvss 9.1epss 0.02
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
- risk 0.67cvss 9.8epss 0.36
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
- risk 0.69cvss 9.8epss 0.67
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
- risk 0.68cvss 9.8epss 0.48
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
- risk 0.64cvss 9.8epss 0.04
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- risk 0.64cvss 9.9epss 0.02
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata…
- risk 0.64cvss 9.8epss 0.01
PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.
- risk 0.64cvss 9.8epss 0.01
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.
- risk 0.59cvss 9.1epss 0.01
There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
- risk 0.64cvss 9.8epss 0.01
There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.64cvss 9.8epss 0.01
There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.
- risk 0.59cvss 9.1epss 0.01
There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
- risk 0.64cvss 9.8epss 0.01
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
- risk 0.64cvss 9.8epss 0.01
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm…
- risk 0.64cvss 9.8epss 0.01
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.
- risk 0.70cvss 9.8epss 0.78
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to…
- risk 0.73cvss 9.8epss 0.81
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL…
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.