Show filters
1,869 Total Results
Displaying 111-120 of 1,869
Sort by:
Attacker Value
Unknown

CVE-2022-4138

Disclosure Date: February 13, 2023 (last updated February 24, 2025)
A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads a file to a malicious project.
Attacker Value
Unknown

CVE-2022-41134

Disclosure Date: February 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exit Intent, Newsletter Popups, Gamification & Opt-in Forms plugin <= 1.0.15 versions.
Attacker Value
Unknown

CVE-2022-34448

Disclosure Date: February 11, 2023 (last updated February 24, 2025)
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions.
Attacker Value
Unknown

CVE-2022-3568

Disclosure Date: February 10, 2023 (last updated February 24, 2025)
The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Attacker Value
Unknown

CVE-2022-41620

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.
Attacker Value
Unknown

CVE-2022-45191

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values.
Attacker Value
Unknown

CVE-2023-0735

Disclosure Date: February 07, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.
Attacker Value
Unknown

CVE-2022-27628

Disclosure Date: February 06, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions.
Attacker Value
Unknown

CVE-2023-0674

Disclosure Date: February 04, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
Attacker Value
Unknown

CVE-2021-37234

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.