Show filters
979 Total Results
Displaying 521-530 of 979
Sort by:
Attacker Value
Unknown

CVE-2022-2638

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server
Attacker Value
Unknown

CVE-2020-27836

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..
Attacker Value
Unknown

CVE-2022-35167

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
Attacker Value
Unknown

CVE-2022-28710

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2022-32777

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerabilty is for the session cookie which can be leaked via JavaScript.
Attacker Value
Unknown

CVE-2022-32761

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2022-32778

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerability is for the pass cookie, which contains the hashed password and can be leaked via JavaScript.
Attacker Value
Unknown

CVE-2020-1754

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
Attacker Value
Unknown

CVE-2022-22411

Disclosure Date: August 04, 2022 (last updated February 24, 2025)
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.
Attacker Value
Unknown

CVE-2022-36800

Disclosure Date: August 03, 2022 (last updated February 24, 2025)
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.