Show filters
687 Total Results
Displaying 81-90 of 687
Sort by:
Attacker Value
Unknown

CVE-2022-1936

Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any location even when IP address restrictions were configured
Attacker Value
Unknown

CVE-2022-1935

Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any location even when IP address restrictions were configured
Attacker Value
Unknown

CVE-2022-1589

Disclosure Date: May 30, 2022 (last updated February 23, 2025)
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
Attacker Value
Unknown

CVE-2022-26767

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.
Attacker Value
Unknown

CVE-2022-30016

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.
Attacker Value
Unknown

CVE-2022-22978

Disclosure Date: May 19, 2022 (last updated February 23, 2025)
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Attacker Value
Unknown

CVE-2021-3956

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An unauthenticated user can gain read-only access to XCC in such a configuration, thereby allowing the XCC device configuration to be viewed but not changed. XCC devices configured to use local authentication, LDAP Authentication + Authorization Mode, or LDAP servers that support only “authenticated bind” and/or “anonymous bind” are not affected.
Attacker Value
Unknown

CVE-2022-1706

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Attacker Value
Unknown

CVE-2022-1753

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.
Attacker Value
Unknown

CVE-2022-1553

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.