Show filters
1,043 Total Results
Displaying 101-110 of 1,043
Sort by:
Attacker Value
Unknown

CVE-2022-3512

Disclosure Date: October 28, 2022 (last updated February 24, 2025)
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint.
Attacker Value
Unknown

CVE-2022-39329

Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.
Attacker Value
Unknown

CVE-2022-39340

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.
Attacker Value
Unknown

CVE-2022-41797

Disclosure Date: October 24, 2022 (last updated February 24, 2025)
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
Attacker Value
Unknown

CVE-2022-40223

Disclosure Date: October 24, 2022 (last updated February 24, 2025)
Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.
Attacker Value
Unknown

CVE-2022-36404

Disclosure Date: October 20, 2022 (last updated February 24, 2025)
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.
Attacker Value
Unknown

CVE-2022-24669

Disclosure Date: October 20, 2022 (last updated February 24, 2025)
It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be used to probe internal network services.
Attacker Value
Unknown

CVE-2022-43431

Disclosure Date: October 19, 2022 (last updated February 24, 2025)
Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-43427

Disclosure Date: October 19, 2022 (last updated February 24, 2025)
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-43421

Disclosure Date: October 19, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects whose configured repository matches the attacker-specified value.