Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29817 1 Jetbrains 1 Intellij Idea 2022-05-05 4.3 MEDIUM 6.1 MEDIUM
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
CVE-2022-29820 1 Jetbrains 1 Pycharm 2022-05-05 3.3 LOW 3.5 LOW
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
CVE-2021-45842 1 Terra-master 3 F2-210, F4-210, Tos 2022-05-05 5.0 MEDIUM 7.5 HIGH
It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS endpoint.
CVE-2022-27135 1 Xpdfreader 1 Xpdf 2022-05-05 4.3 MEDIUM 5.5 MEDIUM
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.
CVE-2022-27103 1 Element-plus 1 Element-plus 2022-05-05 4.3 MEDIUM 6.1 MEDIUM
element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.
CVE-2022-29819 1 Jetbrains 1 Intellij Idea 2022-05-05 4.4 MEDIUM 7.7 HIGH
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
CVE-2022-29818 1 Jetbrains 1 Intellij Idea 2022-05-05 3.6 LOW 7.1 HIGH
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
CVE-2022-29821 1 Jetbrains 1 Pycharm 2022-05-05 4.4 MEDIUM 7.7 HIGH
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
CVE-2022-1396 1 Donorbox 1 Donorbox 2022-05-05 3.5 LOW 4.8 MEDIUM
The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed
CVE-2022-1391 1 Kanev 1 Cab Fare Calculator 2022-05-05 7.5 HIGH 9.8 CRITICAL
The Cab fare calculator WordPress plugin through 1.0.3 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.
CVE-2021-45836 1 Terra-master 3 F2-210, F4-210, Tos 2022-05-05 9.0 HIGH 8.8 HIGH
An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.
CVE-2021-24805 1 Designwall 1 Dw Question \& Answer 2022-05-05 4.3 MEDIUM 4.3 MEDIUM
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status.
CVE-2021-24800 1 Designwall 1 Dw Question \& Answer 2022-05-05 4.0 MEDIUM 4.3 MEDIUM
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
CVE-2022-28094 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2022-05-05 4.3 MEDIUM 6.1 MEDIUM
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
CVE-2022-28093 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2022-05-05 7.5 HIGH 9.8 CRITICAL
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
CVE-2021-38162 1 Sap 1 Web Dispatcher 2022-05-05 7.5 HIGH 9.4 CRITICAL
SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes allow an unauthenticated attacker to submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify any information on the server or consume server resources making it temporarily unavailable.
CVE-2022-28525 1 Ed01-cms Project 1 Ed01-cms 2022-05-04 6.5 MEDIUM 8.8 HIGH
ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.
CVE-2022-28524 1 Ed01-cms Project 1 Ed01-cms 2022-05-04 7.5 HIGH 9.8 CRITICAL
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.
CVE-2022-28918 1 Njtech 1 Greencms 2022-05-04 5.5 MEDIUM 8.1 HIGH
GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=.
CVE-2022-26564 1 Digitaldruid 1 Hoteldruid 2022-05-04 4.3 MEDIUM 6.1 MEDIUM
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
CVE-2022-28892 1 Mahara 1 Mahara 2022-05-04 6.8 MEDIUM 8.8 HIGH
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
CVE-2022-29415 1 Ravpage Project 1 Ravpage 2022-05-04 4.3 MEDIUM 6.1 MEDIUM
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 at WordPress.
CVE-2022-28058 1 Verydows 1 Verydows 2022-05-04 5.5 MEDIUM 8.1 HIGH
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.
CVE-2022-28448 1 Nopcommerce 1 Nopcommerce 2022-05-04 3.5 LOW 5.4 MEDIUM
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
CVE-2022-28059 1 Verydows 1 Verydows 2022-05-04 5.5 MEDIUM 8.1 HIGH
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.
CVE-2022-1461 1 Open-emr 1 Openemr 2022-05-04 4.0 MEDIUM 6.5 MEDIUM
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-28449 1 Nopcommerce 1 Nopcommerce 2022-05-04 4.3 MEDIUM 6.1 MEDIUM
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
CVE-2022-1459 1 Open-emr 1 Openemr 2022-05-04 5.5 MEDIUM 8.3 HIGH
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-28521 1 Zcms Project 1 Zcms 2022-05-04 7.5 HIGH 9.8 CRITICAL
ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.
CVE-2022-28450 1 Nopcommerce 1 Nopcommerce 2022-05-04 3.5 LOW 5.4 MEDIUM
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
CVE-2022-28522 1 Zcms Project 1 Zcms 2022-05-04 3.5 LOW 5.4 MEDIUM
ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add.
CVE-2021-41161 1 Combodo 1 Itop 2022-05-04 4.3 MEDIUM 6.1 MEDIUM
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2022-20778 1 Cisco 1 Webex Meetings 2022-05-04 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the authentication component of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the authentication component of Cisco Webex Meetings. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
CVE-2022-20773 1 Cisco 1 Umbrella 2022-05-04 6.8 MEDIUM 8.1 HIGH
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this vulnerability by performing a man-in-the-middle attack on an SSH connection to the Umbrella VA. A successful exploit could allow the attacker to learn the administrator credentials, change configurations, or reload the VA. Note: SSH is not enabled by default on the Umbrella VA.
CVE-2022-20783 1 Cisco 2 Roomos, Telepresence Collaboration Endpoint 2022-05-04 7.8 HIGH 7.5 HIGH
A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted H.323 traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to either reboot normally or reboot into maintenance mode, which could result in a DoS condition on the device.
CVE-2022-1458 1 Open-emr 1 Openemr 2022-05-04 3.5 LOW 5.4 MEDIUM
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-20787 1 Cisco 1 Unified Communications Manager 2022-05-04 6.0 MEDIUM 6.8 MEDIUM
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.
CVE-2022-1457 1 Facturascripts 1 Facturascripts 2022-05-04 3.5 LOW 5.4 MEDIUM
Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascripts prior to 2022.04. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.
CVE-2022-29264 1 Coreboot 1 Coreboot 2022-05-04 7.5 HIGH 9.8 CRITICAL
An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.
CVE-2021-40680 1 Articatech 1 Web Proxy 2022-05-04 5.5 MEDIUM 8.1 HIGH
There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.
CVE-2022-20786 1 Cisco 1 Unified Communications Manager Im And Presence Service 2022-05-04 5.5 MEDIUM 8.1 HIGH
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system.
CVE-2022-20805 1 Cisco 1 Umbrella Secure Web Gateway 2022-05-04 2.7 LOW 4.1 MEDIUM
A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authenticated, adjacent attacker to bypass the SSL decryption and content filtering policies on an affected system. This vulnerability is due to how the decryption function uses the TLS Sever Name Indication (SNI) extension of an HTTP request to discover the destination domain and determine if the request needs to be decrypted. An attacker could exploit this vulnerability by sending a crafted request over TLS from a client to an unknown or controlled URL. A successful exploit could allow an attacker to bypass the decryption process of Cisco Umbrella SWG and allow malicious content to be downloaded to a host on a protected network. There are workarounds that address this vulnerability.
CVE-2022-22815 2 Debian, Python 2 Debian Linux, Pillow 2022-05-04 6.4 MEDIUM 6.5 MEDIUM
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
CVE-2022-20788 1 Cisco 2 Unified Communications Manager, Unity Connection 2022-05-04 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
CVE-2022-0567 1 Ovn 1 Ovn-kubernetes 2022-05-04 6.5 MEDIUM 9.1 CRITICAL
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This issue results in information disclosure and other attacks on other pods that should not be reachable.
CVE-2022-1440 1 Git-interface Project 1 Git-interface 2022-05-04 10.0 HIGH 9.8 CRITICAL
Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.
CVE-2022-1039 1 Redlion 2 Da50n, Da50n Firmware 2022-05-04 10.0 HIGH 9.8 CRITICAL
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of which is by default enabled on trusted interfaces. While the SSH service does not support root login, a user logging in using either of the other Linux accounts may elevate to root access using the su command if they have access to the associated password.
CVE-2022-29603 1 Universis 1 Universis-api 2022-05-04 5.5 MEDIUM 8.1 HIGH
A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API endpoints. A remote authenticated attacker could send crafted SQL statements to a vulnerable endpoint (such as /api/students/me/messages/) to, for example, retrieve personal information or change grades.
CVE-2019-25059 2 Artifex, Debian 2 Ghostscript, Debian Linux 2022-05-04 6.8 MEDIUM 7.8 HIGH
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
CVE-2022-28743 1 Foscam 3 R2c, R2c Application Firmware, R2c System Firmware 2022-05-04 8.5 HIGH 6.6 MEDIUM
Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware patch. The impact of this vulnerability is that the remote attacker could gain full remote access to the IP camera and the underlying Linux system with root permissions. With root access to the camera's Linux OS, an attacker could effectively change the code that is running, add backdoor access, or invade the privacy of the user by accessing the live camera stream.