Show filters
356 Total Results
Displaying 201-210 of 356
Sort by:
Attacker Value
Unknown

CVE-2022-1224

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Attacker Value
Unknown

CVE-2022-0406

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
Attacker Value
Unknown

CVE-2022-0860

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
Attacker Value
Unknown

CVE-2022-0821

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
Attacker Value
Unknown

CVE-2022-0829

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
Attacker Value
Unknown

CVE-2022-0587

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
Attacker Value
Unknown

CVE-2022-24002

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.
Attacker Value
Unknown

CVE-2021-42000

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.
Attacker Value
Unknown

CVE-2022-21196

Disclosure Date: February 03, 2022 (last updated February 23, 2025)
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.
Attacker Value
Unknown

CVE-2021-44204

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287