Search Results (Refine Search)
| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2021-43932 |
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. Published: April 28, 2022; 11:15:09 AM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2021-43930 |
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system. Published: April 28, 2022; 11:15:08 AM -0400 |
V4.0:(not available) V3.1: 4.9 MEDIUM V2.0: 4.0 MEDIUM |
| CVE-2022-28102 |
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php. Published: April 28, 2022; 10:15:07 AM -0400 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0: 3.5 LOW |
| CVE-2022-28101 |
Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection. Published: April 28, 2022; 10:15:07 AM -0400 |
V4.0:(not available) V3.1: 9.0 CRITICAL V2.0: 6.0 MEDIUM |
| CVE-2022-24873 |
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin. Published: April 28, 2022; 10:15:07 AM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2021-41945 |
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. Published: April 28, 2022; 10:15:07 AM -0400 |
V4.0:(not available) V3.1: 9.1 CRITICAL V2.0: 6.4 MEDIUM |
| CVE-2022-29152 |
The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page. Published: April 28, 2022; 9:15:08 AM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2022-24935 |
Lexmark products through 2022-02-10 have Incorrect Access Control. Published: April 28, 2022; 9:15:08 AM -0400 |
V4.0:(not available) V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2021-41921 |
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. Published: April 28, 2022; 9:15:08 AM -0400 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2021-33436 |
NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM. Published: April 28, 2022; 7:15:07 AM -0400 |
V4.0:(not available) V3.1: 7.3 HIGH V2.0: 6.2 MEDIUM |
| CVE-2022-29821 |
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 7.7 HIGH V2.0: 4.4 MEDIUM |
| CVE-2022-29820 |
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 3.5 LOW V2.0: 3.3 LOW |
| CVE-2022-29819 |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 7.7 HIGH V2.0: 4.4 MEDIUM |
| CVE-2022-29818 |
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 7.1 HIGH V2.0: 3.6 LOW |
| CVE-2022-29817 |
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2022-29816 |
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 3.2 LOW V2.0: 2.1 LOW |
| CVE-2022-29815 |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 6.7 MEDIUM V2.0: 4.6 MEDIUM |
| CVE-2022-29814 |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 7.7 HIGH V2.0: 4.4 MEDIUM |
| CVE-2022-29813 |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 6.7 MEDIUM V2.0: 4.6 MEDIUM |
| CVE-2022-29812 |
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient Published: April 28, 2022; 6:15:08 AM -0400 |
V4.0:(not available) V3.1: 2.3 LOW V2.0: 2.1 LOW |