The Wayback Machine - https://web.archive.org/web/20220207075018/http://nvd.nist.gov/
U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.



The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2021-42554 - SMM memory corruption vulnerability allowing a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
    Published: February 02, 2022; 9:15:07 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 10.0 HIGH

  • CVE-2021-42059 - Stack overflow vulnerability that allows a local root user to access UEFI DXE driver and execute arbitrary code.
    Published: February 02, 2022; 9:15:07 PM -0500

    V3.1: 6.7 MEDIUM
    V2.0: 7.2 HIGH

  • CVE-2022-0432 - Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
    Published: February 02, 2022; 5:15:07 PM -0500

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2022-0443 - Use After Free in Conda vim prior to 8.2.
    Published: February 02, 2022; 4:15:07 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2022-22509 - In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
    Published: February 02, 2022; 8:15:08 AM -0500

    V3.1: 8.8 HIGH
    V2.0: 9.0 HIGH

  • CVE-2021-4173 - vim is vulnerable to Use After Free
    Published: December 27, 2021; 8:15:07 AM -0500

    V3.1: 7.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2022-21906 - Windows Defender Application Control Security Feature Bypass Vulnerability.
    Published: January 11, 2022; 4:15:12 PM -0500

    V3.1: 5.5 MEDIUM
    V2.0: 2.1 LOW

  • CVE-2022-22827 - storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    Published: January 10, 2022; 9:12:57 AM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2022-22826 - nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    Published: January 10, 2022; 9:12:57 AM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2022-22825 - lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    Published: January 10, 2022; 9:12:56 AM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2022-22824 - defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    Published: January 10, 2022; 9:12:56 AM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2022-22823 - build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    Published: January 10, 2022; 9:12:56 AM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2022-22822 - addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
    Published: January 10, 2022; 9:12:56 AM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2022-24301 - In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.
    Published: February 02, 2022; 1:15:06 AM -0500

    V3.1: 6.5 MEDIUM
    V2.0: 6.4 MEDIUM

  • CVE-2022-24223 - AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
    Published: February 01, 2022; 2:15:07 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2022-24218 - An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.
    Published: February 01, 2022; 2:15:07 PM -0500

    V3.1: 9.1 CRITICAL
    V2.0: 6.4 MEDIUM

  • CVE-2022-0128 - vim is vulnerable to Out-of-bounds Read
    Published: January 06, 2022; 12:15:07 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2021-46142 - An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
    Published: January 05, 2022; 11:15:06 PM -0500

    V3.1: 5.5 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2021-46141 - An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
    Published: January 05, 2022; 11:15:06 PM -0500

    V3.1: 5.5 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2021-38560 - Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
    Published: February 01, 2022; 11:15:09 AM -0500

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM