Show filters
653 Total Results
Displaying 111-120 of 653
Sort by:
Attacker Value
Unknown
CVE-2022-4807
Disclosure Date: December 28, 2022 (last updated February 24, 2025)
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
0
Attacker Value
Unknown
CVE-2022-41654
Disclosure Date: December 28, 2022 (last updated February 24, 2025)
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-4724
Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
0
Attacker Value
Unknown
CVE-2022-44565
Disclosure Date: December 23, 2022 (last updated February 24, 2025)
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
0
Attacker Value
Unknown
CVE-2022-4689
Disclosure Date: December 23, 2022 (last updated February 24, 2025)
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
0
Attacker Value
Unknown
CVE-2022-4684
Disclosure Date: December 23, 2022 (last updated February 24, 2025)
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
0
Attacker Value
Unknown
CVE-2022-23513
Disclosure Date: December 23, 2022 (last updated February 24, 2025)
Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path:
`/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.
0
Attacker Value
Unknown
CVE-2022-3186
Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's information.
0
Attacker Value
Unknown
CVE-2022-38546
Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode.
0
Attacker Value
Unknown
CVE-2022-4567
Disclosure Date: December 17, 2022 (last updated February 24, 2025)
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
0