| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24043 | Cri | 0.59 | 9.1 | 0.01 | Feb 2, 2022 | A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if… | ||
| CVE-2022-24300 | Cri | 0.00 | 9.8 | 0.02 | Feb 2, 2022 | Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection. | ||
| CVE-2022-24223 | Cri | 0.72 | 9.8 | 0.62 | Feb 1, 2022 | AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. | ||
| CVE-2022-24222 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | ||
| CVE-2022-24221 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. | ||
| CVE-2022-24220 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | ||
| CVE-2022-24219 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | ||
| CVE-2022-24218 | Cri | 0.61 | 9.1 | 0.17 | Feb 1, 2022 | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. | ||
| CVE-2021-46093 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. | ||
| CVE-2021-43510 | Cri | 0.64 | 9.8 | 0.08 | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. | ||
| CVE-2021-43509 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php. | ||
| CVE-2022-0401 | Cri | 0.57 | 9.8 | 0.02 | Feb 1, 2022 | Path Traversal in NPM w-zip prior to 1.0.12. | ||
| CVE-2022-0320 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2022 | The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server,… | ||
| CVE-2021-24814 | Cri | 0.63 | 9.6 | 0.02 | Feb 1, 2022 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be… | ||
| CVE-2021-24762 | Cri | 0.74 | 9.8 | 0.87 | Feb 1, 2022 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection. | ||
| CVE-2022-23603 | Cri | 0.00 | 9.9 | 0.01 | Feb 1, 2022 | iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There are no known workarounds… | ||
| CVE-2022-24263 | Cri | 0.67 | 9.8 | 0.08 | Jan 31, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter. | ||
| CVE-2021-31617 | Cri | 0.64 | 9.8 | 0.02 | Jan 31, 2022 | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution. | ||
| CVE-2020-36064 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2022 | Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised. | ||
| CVE-2021-45079 | Cri | 0.59 | 9.1 | 0.03 | Jan 31, 2022 | In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication. | ||
| CVE-2022-0339 | Cri | 0.57 | 9.8 | 0.01 | Jan 30, 2022 | Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. | ||
| CVE-2021-46660 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2022 | Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks. | ||
| CVE-2022-24123 | Cri | 0.00 | 9.0 | 0.02 | Jan 29, 2022 | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload. | ||
| CVE-2021-46448 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID. | ||
| CVE-2021-46446 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID. | ||
| CVE-2021-46445 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id. | ||
| CVE-2021-46444 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID. | ||
| CVE-2021-23484 | Cri | 0.57 | 9.8 | 0.02 | Jan 28, 2022 | The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory. | ||
| CVE-2022-21217 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2021-40409 | Cri | 0.64 | 9.8 | 0.04 | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided through the SetDdns API, is… | ||
| CVE-2021-40408 | Cri | 0.64 | 9.8 | 0.04 | Jan 28, 2022 | An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->username variable, that has the value of the userName parameter provided through the SetDdns API, is… | ||
| CVE-2021-22820 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products:… | ||
| CVE-2021-44971 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE. | ||
| CVE-2021-41609 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection. | ||
| CVE-2022-22294 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account. | ||
| CVE-2021-45899 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. | ||
| CVE-2021-45898 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. | ||
| CVE-2022-23097 | Cri | 0.59 | 9.1 | 0.02 | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read. | ||
| CVE-2022-23096 | Cri | 0.59 | 9.1 | 0.03 | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read. | ||
| CVE-2020-25905 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php. | ||
| CVE-2021-45435 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php. | ||
| CVE-2021-44249 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials. | ||
| CVE-2021-46428 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php. | ||
| CVE-2021-46427 | Cri | 0.64 | 9.8 | 0.02 | Jan 27, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php. | ||
| CVE-2021-46377 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2022 | There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser | ||
| CVE-2022-21723 | Cri | 0.00 | 9.1 | 0.04 | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can… | ||
| CVE-2022-21722 | Cri | 0.00 | 9.1 | 0.02 | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP… | ||
| CVE-2022-21686 | Cri | 0.52 | 9.0 | 0.02 | Jan 26, 2022 | PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds. | ||
| CVE-2021-46386 | Cri | 0.64 | 9.8 | 0.03 | Jan 26, 2022 | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload. | ||
| CVE-2022-0362 | Cri | 0.57 | 9.8 | 0.01 | Jan 26, 2022 | SQL Injection in Packagist showdoc/showdoc prior to 2.10.3. |
- risk 0.59cvss 9.1epss 0.01
A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if…
- risk 0.00cvss 9.8epss 0.02
Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
- risk 0.72cvss 9.8epss 0.62
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.
- risk 0.61cvss 9.1epss 0.17
An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.
- risk 0.64cvss 9.8epss 0.08
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.
- risk 0.57cvss 9.8epss 0.02
Path Traversal in NPM w-zip prior to 1.0.12.
- risk 0.64cvss 9.8epss 0.02
The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server,…
- risk 0.63cvss 9.6epss 0.02
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be…
- risk 0.74cvss 9.8epss 0.87
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
- risk 0.00cvss 9.9epss 0.01
iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There are no known workarounds…
- risk 0.67cvss 9.8epss 0.08
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
- risk 0.64cvss 9.8epss 0.02
In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution.
- risk 0.64cvss 9.8epss 0.01
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
- risk 0.59cvss 9.1epss 0.03
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
- risk 0.57cvss 9.8epss 0.01
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
- risk 0.64cvss 9.8epss 0.01
Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.
- risk 0.00cvss 9.0epss 0.02
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload.
- risk 0.64cvss 9.8epss 0.01
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.
- risk 0.64cvss 9.8epss 0.01
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.
- risk 0.64cvss 9.8epss 0.01
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.
- risk 0.64cvss 9.8epss 0.01
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID.
- risk 0.57cvss 9.8epss 0.02
The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.
- risk 0.64cvss 9.8epss 0.01
An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.04
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided through the SetDdns API, is…
- risk 0.64cvss 9.8epss 0.04
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->username variable, that has the value of the userName parameter provided through the SetDdns API, is…
- risk 0.64cvss 9.8epss 0.01
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products:…
- risk 0.64cvss 9.8epss 0.02
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
- risk 0.64cvss 9.8epss 0.02
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account.
- risk 0.64cvss 9.8epss 0.02
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
- risk 0.59cvss 9.1epss 0.02
An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.
- risk 0.59cvss 9.1epss 0.03
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.
- risk 0.64cvss 9.8epss 0.02
Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.
- risk 0.64cvss 9.8epss 0.01
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser
- risk 0.00cvss 9.1epss 0.04
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can…
- risk 0.00cvss 9.1epss 0.02
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP…
- risk 0.52cvss 9.0epss 0.02
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.
- risk 0.64cvss 9.8epss 0.03
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
- risk 0.57cvss 9.8epss 0.01
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.