Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44992 1 Jerryscript 1 Jerryscript 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript 3.0.0.
CVE-2021-22045 2 Apple, Vmware 5 Mac Os X, Cloud Foundation, Esxi and 2 more 2022-01-27 6.9 MEDIUM 7.8 HIGH
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor from a virtual machine.
CVE-2021-46307 1 Projectworlds 1 Online Examination System 2022-01-27 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
CVE-2021-46201 1 Online Resort Management System Project 1 Online Resort Management System 2022-01-27 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.
CVE-2021-46323 1 Espruino 1 Espruino 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Espruino 2v11.251 was discovered to contain a SEGV vulnerability via src/jsinteractive.c in jsiGetDeviceFromClass.
CVE-2021-46324 1 Espruino 1 Espruino 2022-01-27 6.8 MEDIUM 7.8 HIGH
Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
CVE-2021-46325 1 Espruino 1 Espruino 2022-01-27 6.8 MEDIUM 7.8 HIGH
Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.
CVE-2021-46198 1 Courier Management System Project 1 Courier Management System 2022-01-27 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.
CVE-2022-0319 2 Canonical, Vim 2 Ubuntu Linux, Vim 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Out-of-bounds Read in vim/vim prior to 8.2.
CVE-2021-25073 1 Webmaster-source 1 Wp125 2022-01-27 6.8 MEDIUM 8.8 HIGH
The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack
CVE-2021-25062 1 Villatheme 1 Orders Tracking For Woocommerce 2022-01-27 4.3 MEDIUM 6.1 MEDIUM
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2021-25008 1 Codesnippets 1 Code Snippets 2022-01-27 4.3 MEDIUM 6.1 MEDIUM
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
CVE-2022-21704 1 Log4js Project 1 Log4js 2022-01-27 2.1 LOW 5.5 MEDIUM
log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.
CVE-2021-24936 1 Wp Extra File Types Project 1 Wp Extra File Types 2022-01-27 6.0 MEDIUM 8.0 HIGH
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
CVE-2021-24865 1 Acf-extended 1 Advanced Custom Fields\ 2022-01-27 6.5 MEDIUM 7.2 HIGH
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
CVE-2021-24858 1 Accesspressthemes 1 Wp Cookie User Info 2022-01-27 6.5 MEDIUM 7.2 HIGH
The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection
CVE-2021-24696 1 Tipsandtricks-hq 1 Simple Download Monitor 2022-01-27 6.8 MEDIUM 8.8 HIGH
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
CVE-2021-24694 1 Tipsandtricks-hq 1 Simple Download Monitor 2022-01-27 3.5 LOW 5.4 MEDIUM
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.
CVE-2020-19860 1 Nlnetlabs 1 Ldns 2022-01-27 4.3 MEDIUM 6.5 MEDIUM
When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.
CVE-2021-24423 1 Updraftplus 1 Updraftplus 2022-01-27 3.5 LOW 4.8 MEDIUM
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue
CVE-2022-21933 1 Asus 26 Pa90, Pa90 Firmware, Pb50 and 23 more 2022-01-27 7.2 HIGH 7.8 HIGH
ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.
CVE-2022-23857 1 Navidrome 1 Navidrome 2022-01-27 4.0 MEDIUM 6.5 MEDIUM
model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive information such as the users' encrypted passwords).
CVE-2021-46024 1 Projectworlds 1 Online-shopping-webvsite-in-php 2022-01-27 7.5 HIGH 9.8 CRITICAL
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
CVE-2021-45380 1 Appcms 1 Appcms 2022-01-27 4.3 MEDIUM 6.1 MEDIUM
AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
CVE-2022-23119 2 Linux, Trendmicro 2 Linux Kernel, Deep Security Agent 2022-01-27 4.3 MEDIUM 7.5 HIGH
A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the target Deep Security Manager (DSM) or the target agent must be not yet activated or configured in order to exploit this vulnerability.
CVE-2022-23120 2 Linux, Trendmicro 2 Linux Kernel, Deep Security Agent 2022-01-27 6.9 MEDIUM 7.8 HIGH
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.
CVE-2021-4103 1 B3log 1 Vditor 2022-01-27 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.
CVE-2021-4172 1 Showdoc 1 Showdoc 2022-01-27 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2021-41550 1 Leostream 1 Connection Broker 2022-01-27 6.5 MEDIUM 7.2 HIGH
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
CVE-2021-46482 1 Jsish 1 Jsish 2022-01-27 6.8 MEDIUM 7.8 HIGH
Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
CVE-2021-46483 1 Jsish 1 Jsish 2022-01-27 6.8 MEDIUM 7.8 HIGH
Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
CVE-2021-46481 1 Jsish 1 Jsish 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.
CVE-2021-46480 1 Jsish 1 Jsish 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46478 1 Jsish 1 Jsish 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46474 1 Jsish 1 Jsish 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2021-46475 1 Jsish 1 Jsish 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2022-22553 1 Dell 1 Emc Appsync 2022-01-27 7.5 HIGH 9.8 CRITICAL
Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing. Account takeover is possible if weak passwords are used by users.
CVE-2022-22552 1 Dell 1 Emc Appsync 2022-01-27 5.8 MEDIUM 6.1 MEDIUM
Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker could potentially exploit this vulnerability to trick the victim into executing state changing operations.
CVE-2021-46477 1 Jsish 1 Jsish 2022-01-27 4.3 MEDIUM 5.5 MEDIUM
Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2022-22551 1 Dell 1 Emc Appsync 2022-01-27 5.8 MEDIUM 8.8 HIGH
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
CVE-2020-19858 1 Plutinosoft 1 Platinum 2022-01-27 5.0 MEDIUM 7.5 HIGH
Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.
CVE-2021-43113 1 Itextpdf 1 Itext 2022-01-27 7.5 HIGH 9.8 CRITICAL
iTextPDF in iText 7 and up to 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
CVE-2020-4879 2 Ibm, Microsoft 2 Cognos Controller, Windows 2022-01-27 7.5 HIGH 9.8 CRITICAL
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.
CVE-2020-4877 2 Ibm, Microsoft 2 Cognos Controller, Windows 2022-01-27 7.5 HIGH 9.8 CRITICAL
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.
CVE-2022-0318 1 Vim 1 Vim 2022-01-27 7.5 HIGH 9.8 CRITICAL
Heap-based Buffer Overflow in vim/vim prior to 8.2.
CVE-2022-23365 1 Hms Project 1 Hms 2022-01-27 7.5 HIGH 9.8 CRITICAL
HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.
CVE-2022-23364 1 Hms Project 1 Hms 2022-01-27 7.5 HIGH 9.8 CRITICAL
HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.
CVE-2021-39480 1 Bingrep Project 1 Bingrep 2022-01-27 5.0 MEDIUM 7.5 HIGH
Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).
CVE-2022-23363 1 Online Banking System Project 1 Online Banking System 2022-01-27 7.5 HIGH 9.8 CRITICAL
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.
CVE-2022-21701 1 Istio 1 Istio 2022-01-27 6.0 MEDIUM 8.8 HIGH
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects can escalate this privilege to create other resources that they may not have access to, such as `Pod`. This vulnerability impacts only an Alpha level feature, the Kubernetes Gateway API. This is not the same as the Istio Gateway type (gateways.networking.istio.io), which is not vulnerable. Users are advised to upgrade to resolve this issue. Users unable to upgrade should implement any of the following which will prevent this vulnerability: Remove the gateways.gateway.networking.k8s.io CustomResourceDefinition, set PILOT_ENABLE_GATEWAY_API_DEPLOYMENT_CONTROLLER=true environment variable in Istiod, or remove CREATE permissions for gateways.gateway.networking.k8s.io objects from untrusted users.