Unknown · CVSS Not scored
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report.
Published Apr 14, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Published Apr 11, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
Published Apr 13, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a quiz-taker to access print and copy functionality via the browser’s right click menu even when “Disable Right Click” is enabled on the quiz.
Published Apr 19, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
Published Apr 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.
Published Apr 8, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the capture command parameters. Command output will be shown on the Serial interface of the device. Exploitation requires both credentials and physical access.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.
Published Apr 13, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter.
Published Apr 15, 2022 · Updated Aug 4, 2024
High · CVSS 8
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
Published Apr 30, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve privilege escalation on the web server of certain devices due to improper access control vulnerability in the engineering system software. The attacker needs to have direct access to the impacted web server.
Published Apr 12, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.6
A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
Published Apr 30, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.
Published Apr 29, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".
Published Apr 29, 2022 · Updated Aug 4, 2024
High · CVSS 7.7
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
Published Apr 30, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.6
A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
Published Apr 30, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
Published Apr 28, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
Published Apr 8, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recursive call to the new opt() function.
Published Apr 5, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Veritas NetBackup OpsCenter Analytics 9.1 allows XSS via the NetBackup Master Server Name, Display Name, NetBackup User Name, or NetBackup Password field during a Settings/Configuration Add operation.
Published Apr 19, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
Published Apr 27, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.
Published Apr 12, 2022 · Updated Aug 4, 2024
High · CVSS 8.1
There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.
Published Apr 25, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
Published Apr 8, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes when the patient profile is loaded, which could be used in a XSS attack.
Published Apr 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
Published Apr 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. This response can be read in an intercepting proxy or by viewing the page source. Sensitive information returned in responses includes patient PII and medication records or history.
Published Apr 6, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
Published Apr 11, 2022 · Updated Aug 4, 2024
Medium · CVSS 6.5
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malicious code into projects without being noticed in merge request or source code viewer UI.
Published Apr 1, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209966086
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-208277166References: Upstream kernel
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215002587
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-200288596
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In TBD of TBD, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205522359References: N/A
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-212694559
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-193790350
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216792660References: N/A
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205837191
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-209446496
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In ion_ioctl of ion-ioctl.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-209791720References: Upstream kernel
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213339151References: Upstream kernel
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-209607104
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213169612
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-205836329
Published Apr 12, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special js code.
Published Apr 5, 2022 · Updated Aug 4, 2024