Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-23972 1 Mozilla 1 Firefox 2022-05-23 6.8 MEDIUM 8.8 HIGH
One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.
CVE-2021-23974 1 Mozilla 1 Firefox 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.
CVE-2022-23742 2 Checkpoint, Microsoft 2 Endpoint Security, Windows 2022-05-23 4.6 MEDIUM 7.8 HIGH
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.
CVE-2022-30413 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2022-05-23 7.5 HIGH 9.8 CRITICAL
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application.
CVE-2022-30412 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2022-05-23 6.5 MEDIUM 7.2 HIGH
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.php?id=.
CVE-2022-30411 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2022-05-23 6.5 MEDIUM 7.2 HIGH
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=.
CVE-2022-30414 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2022-05-23 6.5 MEDIUM 7.2 HIGH
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=applications/view_application&id=.
CVE-2021-40399 1 Wps 1 Wps Office 2022-05-23 6.8 MEDIUM 7.8 HIGH
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
CVE-2021-33149 1 Intel 16 Atom Processors, Atom Processors Firmware, Celeron Processors and 13 more 2022-05-23 2.1 LOW 5.5 MEDIUM
Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
CVE-2021-42969 1 Anaconda 1 Anaconda3 2022-05-23 9.3 HIGH 8.8 HIGH
Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.
CVE-2022-29433 1 Donations Project 1 Donations 2022-05-23 3.5 LOW 5.4 MEDIUM
Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.
CVE-2022-21136 1 Intel 292 Core I9-7900x, Core I9-7900x Firmware, Core I9-7920x and 289 more 2022-05-23 4.9 MEDIUM 5.5 MEDIUM
Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access.
CVE-2022-30417 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2022-05-23 6.5 MEDIUM 7.2 HIGH
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=.
CVE-2022-30415 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2022-05-23 6.5 MEDIUM 7.2 HIGH
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.php?id=.
CVE-2022-21147 1 Estsoft 1 Alyac 2022-05-23 4.3 MEDIUM 5.5 MEDIUM
An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. A specially-crafted PE file can trigger this vulnerability to cause denial of service and termination of malware scan. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-25591 1 Blogengine 1 Blogengine.net 2022-05-23 6.4 MEDIUM 9.1 CRITICAL
BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.
CVE-2022-21182 1 Inhandnetworks 2 Inrouter302, Inrouter302 Firmware 2022-05-23 6.5 MEDIUM 8.8 HIGH
A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2021-46786 1 Huawei 3 Emui, Harmonyos, Magic Ui 2022-05-23 7.5 HIGH 9.8 CRITICAL
The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation of this vulnerability may cause out-of-bounds memory access.
CVE-2021-46787 1 Huawei 3 Emui, Harmonyos, Magic Ui 2022-05-23 5.0 MEDIUM 7.5 HIGH
The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.
CVE-2021-46788 1 Huawei 2 Emui, Magic Ui 2022-05-23 5.0 MEDIUM 7.5 HIGH
Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.
CVE-2022-22796 1 Sysaid 1 Sysaid 2022-05-23 10.0 HIGH 9.8 CRITICAL
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.
CVE-2022-21237 1 Intel 118 Lapbc510, Lapbc510 Firmware, Lapbc710 and 115 more 2022-05-23 6.1 MEDIUM 6.7 MEDIUM
Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2022-22260 1 Huawei 2 Emui, Harmonyos 2022-05-23 6.4 MEDIUM 9.1 CRITICAL
The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and availability.
CVE-2022-29789 1 Huawei 2 Emui, Harmonyos 2022-05-23 5.0 MEDIUM 7.5 HIGH
The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services.
CVE-2022-22261 1 Huawei 2 Emui, Harmonyos 2022-05-23 5.0 MEDIUM 7.5 HIGH
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
CVE-2022-29791 1 Huawei 2 Emui, Harmonyos 2022-05-23 5.0 MEDIUM 7.5 HIGH
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
CVE-2022-29790 1 Huawei 2 Emui, Harmonyos 2022-05-23 5.0 MEDIUM 7.5 HIGH
The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.
CVE-2022-29792 1 Huawei 2 Emui, Harmonyos 2022-05-23 5.0 MEDIUM 7.5 HIGH
The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-29368 1 Moddable 1 Moddable 2022-05-23 5.8 MEDIUM 7.1 HIGH
Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.
CVE-2022-29794 1 Huawei 2 Emui, Harmonyos 2022-05-23 7.5 HIGH 9.8 CRITICAL
The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.
CVE-2022-29796 1 Huawei 2 Emui, Harmonyos 2022-05-23 5.0 MEDIUM 7.5 HIGH
The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.
CVE-2022-29795 1 Huawei 2 Emui, Harmonyos 2022-05-23 5.0 MEDIUM 7.5 HIGH
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
CVE-2022-21238 1 Inhandnetworks 2 Inrouter302, Inrouter302 Firmware 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-21809 1 Inhandnetworks 2 Inrouter302, Inrouter302 Firmware 2022-05-23 5.5 MEDIUM 8.1 HIGH
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.
CVE-2022-30404 1 College Management System Project 1 College Management System 2022-05-23 6.5 MEDIUM 7.2 HIGH
College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.
CVE-2022-30403 1 Merchandise Online Store Product 1 Merchandise Online Store 2022-05-23 6.5 MEDIUM 7.2 HIGH
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=products&c=.
CVE-2022-1714 1 Radare 1 Radare2 2022-05-23 3.6 LOW 7.1 HIGH
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.
CVE-2022-28819 3 Adobe, Apple, Microsoft 3 Character Animator, Macos, Windows 2022-05-23 9.3 HIGH 7.8 HIGH
Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file.
CVE-2022-22139 1 Intel 1 Extreme Tuning Utility 2022-05-23 4.4 MEDIUM 7.3 HIGH
Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-28818 1 Adobe 1 Coldfusion 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
CVE-2022-30489 1 Wavlink 2 Wn535g3, Wn535g3 Firmware 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.
CVE-2022-30407 1 Pharmacy Sales And Inventory System Project 1 Pharmacy Sales And Inventory System 2022-05-23 7.5 HIGH 9.8 CRITICAL
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
CVE-2021-22531 1 Microfocus 1 Access Manager 2022-05-23 4.3 MEDIUM 6.1 MEDIUM
A bug exist in the input parameter of Access Manager that allows supply of invalid character to trigger cross-site scripting vulnerability. This affects NetIQ Access Manager 4.5 and 5.0
CVE-2022-29363 1 Phpok 1 Phpok 2022-05-23 7.5 HIGH 9.8 CRITICAL
Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability allows attackers to getshell via writing arbitrary files.
CVE-2022-30408 1 Covid 19 Travel Pass Management System Project 1 Covid 19 Travel Pass Management System 2022-05-23 5.5 MEDIUM 6.5 MEDIUM
Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img.
CVE-2022-27172 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2022-05-23 6.5 MEDIUM 8.8 HIGH
A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2022-24297 1 Intel 118 Lapbc510, Lapbc510 Firmware, Lapbc710 and 115 more 2022-05-23 4.6 MEDIUM 6.7 MEDIUM
Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2022-24382 1 Intel 118 Lapbc510, Lapbc510 Firmware, Lapbc710 and 115 more 2022-05-23 4.6 MEDIUM 6.7 MEDIUM
Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2021-41945 1 Encode 1 Httpx 2022-05-23 6.4 MEDIUM 9.1 CRITICAL
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.
CVE-2021-3623 2 Libtpms Project, Redhat 2 Libtpms, Enterprise Linux 2022-05-23 6.4 MEDIUM 8.2 HIGH
A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.