Show filters
728 Total Results
Displaying 61-70 of 728
Sort by:
Attacker Value
Unknown
CVE-2022-0398
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary website
0
Attacker Value
Unknown
CVE-2022-0363
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.
0
Attacker Value
Unknown
CVE-2022-0287
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog
0
Attacker Value
Unknown
CVE-2022-25342
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset path. By not verifying permissions for access to resources, it allows a potential attacker to view pages that are not allowed.
0
Attacker Value
Unknown
CVE-2022-1384
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.
0
Attacker Value
Unknown
CVE-2022-1329
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
0
Attacker Value
Unknown
CVE-2022-1054
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events
0
Attacker Value
Unknown
CVE-2022-1020
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument
0
Attacker Value
Unknown
CVE-2022-29051
Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Missing permission checks in Jenkins Publish Over FTP Plugin 1.16 and earlier allow attackers with Overall/Read permission to connect to an FTP server using attacker-specified credentials.
0
Attacker Value
Unknown
CVE-2022-27669
Disclosure Date: April 12, 2022 (last updated February 23, 2025)
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
0