Show filters
973 Total Results
Displaying 91-100 of 973
Sort by:
Attacker Value
Unknown

CVE-2022-35249

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
Attacker Value
Unknown

CVE-2022-35247

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients.
Attacker Value
Unknown

CVE-2022-32220

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
Attacker Value
Unknown

CVE-2022-36340

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
Attacker Value
Unknown

CVE-2021-41803

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."
Attacker Value
Unknown

CVE-2021-39190

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.
Attacker Value
Unknown

CVE-2022-38512

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
Attacker Value
Unknown

CVE-2022-39975

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
Attacker Value
Unknown

CVE-2022-41254

Disclosure Date: September 21, 2022 (last updated February 24, 2025)
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-41252

Disclosure Date: September 21, 2022 (last updated February 24, 2025)
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.