CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2022-27164 CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers | 9.8 | CRITICAL | — | 0 |
| CVE-2022-27165 CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus | 9.8 | CRITICAL | — | 0 |
| CVE-2022-27472 SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28528 bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | 8.8 | HIGH | — | 0 |
| CVE-2022-27473 SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28032 AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28033 Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28034 AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28035 Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php | 9.8 | CRITICAL | — | 0 |
| CVE-2022-28036 AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php | 9.8 | CRITICAL | — | 0 |
| CVE-2021-0694 In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could... | 7.8 | HIGH | — | 0 |
| CVE-2021-0707 In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User in... | 7.8 | HIGH | — | 0 |
| CVE-2021-36914 Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.2.11. | 6.1 | MEDIUM | — | 0 |
| CVE-2021-39794 In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local e... | 7.8 | HIGH | — | 0 |
| CVE-2021-39796 In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation o... | 7.3 | HIGH | — | 0 |
| CVE-2021-39797 In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional executio... | 7.8 | HIGH | — | 0 |
| CVE-2021-39798 In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges ne... | 7.8 | HIGH | — | 0 |
| CVE-2021-39799 In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution pr... | 7.8 | HIGH | — | 0 |
| CVE-2021-39800 In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. U... | 5.5 | MEDIUM | — | 0 |
| CVE-2021-39801 In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti... | 7.8 | HIGH | — | 0 |
| CVE-2021-39802 In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution pr... | 7.8 | HIGH | — | 0 |
| CVE-2021-39803 In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User in... | 6.5 | MEDIUM | — | 0 |
| CVE-2021-39804 In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileg... | 6.5 | MEDIUM | — | 0 |
| CVE-2021-39805 In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure through Bluetooth with no additional exe... | 6.5 | MEDIUM | — | 0 |
| CVE-2021-39807 In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from... | 7.8 | HIGH | — | 0 |
| CVE-2021-39808 In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to l... | 7.8 | HIGH | — | 0 |
| CVE-2025-30639 Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IDonatePro: from n/a through <= 2.... | N/A | NONE | — | 0 |
| CVE-2021-39809 In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution pri... | 7.5 | HIGH | — | 0 |
| CVE-2021-39812 In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ... | 7.8 | HIGH | — | 0 |
| CVE-2021-39814 In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. Us... | 6.7 | MEDIUM | — | 0 |
| CVE-2021-41004 A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0. | 7.5 | HIGH | — | 0 |
| CVE-2021-41005 A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0. | 6.5 | MEDIUM | — | 0 |
| CVE-2022-26106 When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes tem... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-21155 A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. | 7.5 | HIGH | — | 0 |
| CVE-2022-21168 The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure. | 3.3 | LOW | — | 0 |
| CVE-2022-21202 The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information. | 3.3 | LOW | — | 0 |
| CVE-2022-21214 The affected product is vulnerable to a heap-based buffer overflow, which may lead to code execution. | 7.8 | HIGH | — | 0 |
| CVE-2022-21228 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code. | 7.8 | HIGH | — | 0 |
| CVE-2022-22541 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is t... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-26107 When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporaril... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-23702 A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnerability could be locally exploited to allow an user with Administrator access to ... | 6.7 | MEDIUM | — | 0 |
| CVE-2022-23703 A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update. This would pote... | 7.5 | HIGH | — | 0 |
| CVE-2022-24383 The affected product is vulnerable to an out-of-bounds read, which may result in code execution | 7.8 | HIGH | — | 0 |
| CVE-2022-24812 Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key ar... | 8.0 | HIGH | — | 0 |
| CVE-2022-26105 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user i... | 6.1 | MEDIUM | — | 0 |
| CVE-2022-26108 When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavai... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-26109 When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes tempo... | 6.5 | MEDIUM | — | 0 |
| CVE-2022-27139 An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. NOTE: Vendor states that as outlined in Ghost's sec... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-27140 An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the ... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-27260 An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file. | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.