Show filters
777 Total Results
Displaying 111-120 of 777
Sort by:
Attacker Value
Unknown

CVE-2020-14321

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Attacker Value
Unknown

CVE-2022-1401

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.
Attacker Value
Unknown

CVE-2022-2354

Disclosure Date: August 15, 2022 (last updated February 24, 2025)
The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.
Attacker Value
Unknown

CVE-2022-35692

Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2022-34255

Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to perform an account takeover for a victim. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2022-35487

Disclosure Date: August 08, 2022 (last updated February 24, 2025)
Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment endpoints. This could be abused by an unauthenticated attacker to gain access to attachments, such as emails or attached files.
Attacker Value
Unknown

CVE-2022-33718

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
Attacker Value
Unknown

CVE-2022-2501

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are still required.
Attacker Value
Unknown

CVE-2022-2326

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible to gain access to a private project through an email invite by using other user's email address as an unverified secondary email.
Attacker Value
Unknown

CVE-2022-2095

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's public fingerprint and name when that key has write permission. Note that GitLab never asks for nor stores the private key.