Show filters
465 Total Results
Displaying 61-70 of 465
Sort by:
Attacker Value
Unknown

CVE-2022-32212

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
Attacker Value
Unknown

CVE-2022-1025

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
Attacker Value
Unknown

CVE-2022-31475

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
Attacker Value
Unknown

CVE-2022-33706

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.
Attacker Value
Unknown

CVE-2022-33701

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
Attacker Value
Unknown

CVE-2022-30752

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.
Attacker Value
Unknown

CVE-2022-30751

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.
Attacker Value
Unknown

CVE-2022-30750

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
Attacker Value
Unknown

CVE-2022-31257

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12). In case of access to an active user session in an application that is built with an affected version, it’s possible to change that user’s password bypassing password validations within a Mendix application. This could allow to set weak passwords.
Attacker Value
Unknown

CVE-2022-20859

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.