Show filters
754 Total Results
Displaying 101-110 of 754
Sort by:
Attacker Value
Unknown

CVE-2022-31178

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability has been patched in 4.3.4. Users are advised to upgrade. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2022-31155

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’ saved searches, only overwriting them with attacker-controlled searches. The issue is patched in Sourcegraph version 3.41.0. There is no workaround for this issue and updating to a secure version is highly recommended.
Attacker Value
Unknown

CVE-2022-31154

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the action of the monitor in question. An attacker is not able to read contents of existing code monitors, only override the data. The issue is fixed in Sourcegraph 3.42. There are no workaround for the issue and patching is highly recommended.
Attacker Value
Unknown

CVE-2022-27551

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
Attacker Value
Unknown

CVE-2022-35716

Disclosure Date: July 29, 2022 (last updated February 24, 2025)
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. IBM X-Force ID: 231360.
Attacker Value
Unknown

CVE-2022-22326

Disclosure Date: July 29, 2022 (last updated February 24, 2025)
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
Attacker Value
Unknown

CVE-2022-1499

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
Attacker Value
Unknown

CVE-2022-1309

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Attacker Value
Unknown

CVE-2022-0670

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Attacker Value
Unknown

CVE-2022-0594

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.