Show filters
687 Total Results
Displaying 81-90 of 687
Sort by:
Attacker Value
Unknown
CVE-2022-1936
Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured
0
Attacker Value
Unknown
CVE-2022-1935
Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured
0
Attacker Value
Unknown
CVE-2022-1589
Disclosure Date: May 30, 2022 (last updated February 23, 2025)
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
0
Attacker Value
Unknown
CVE-2022-26767
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.
0
Attacker Value
Unknown
CVE-2022-30016
Disclosure Date: May 23, 2022 (last updated February 23, 2025)
Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.
0
Attacker Value
Unknown
CVE-2022-22978
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
0
Attacker Value
Unknown
CVE-2021-3956
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.
0
Attacker Value
Unknown
CVE-2022-1706
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
0
Attacker Value
Unknown
CVE-2022-1753
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.
0
Attacker Value
Unknown
CVE-2022-1553
Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.
0