Show filters
910 Total Results
Displaying 91-100 of 910
Sort by:
Attacker Value
Unknown
CVE-2022-43415
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2022-3338
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.
0
Attacker Value
Unknown
CVE-2022-41542
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
devhub 0.102.0 was discovered to contain a broken session control.
0
Attacker Value
Unknown
CVE-2022-42341
Disclosure Date: October 14, 2022 (last updated February 24, 2025)
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
0
Attacker Value
Unknown
CVE-2021-27406
Disclosure Date: October 14, 2022 (last updated February 24, 2025)
An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This could result in the attacker achieving execution with privileges of a SYSTEM user.
0
Attacker Value
Unknown
CVE-2022-38419
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
0
Attacker Value
Unknown
CVE-2022-41672
Disclosure Date: October 07, 2022 (last updated February 24, 2025)
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
0
Attacker Value
Unknown
CVE-2022-41291
Disclosure Date: October 06, 2022 (last updated February 24, 2025)
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.
0
Attacker Value
Unknown
CVE-2022-42307
Disclosure Date: October 03, 2022 (last updated February 24, 2025)
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.
0
Attacker Value
Unknown
CVE-2022-42301
Disclosure Date: October 03, 2022 (last updated February 24, 2025)
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.
0