Show filters
654 Total Results
Displaying 51-60 of 654
Sort by:
Attacker Value
Unknown

CVE-2022-0905

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
Attacker Value
Unknown

CVE-2021-41241

Disclosure Date: March 08, 2022 (last updated February 23, 2025)
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted access to the groupfolder but not specific subfolders. Due to a lacking permission check in affected versions, a user could still access these subfolders by copying the groupfolder to another location. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the "groupfolders" application in the admin settings.
Attacker Value
Unknown

CVE-2021-41239

Disclosure Date: March 08, 2022 (last updated February 23, 2025)
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings where disabled. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. There are no known workarounds.
Attacker Value
Unknown

CVE-2022-0756

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
Attacker Value
Unknown

CVE-2022-0755

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
Attacker Value
Unknown

CVE-2022-0163

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.
Attacker Value
Unknown

CVE-2021-25087

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
Attacker Value
Unknown

CVE-2021-3656

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.
Attacker Value
Unknown

CVE-2022-23709

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.
Attacker Value
Unknown

CVE-2022-0492

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.