Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown
CVE-2022-23652
Disclosure Date: February 22, 2022 (last updated February 23, 2025)
capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a proper authentication mechanism may use a malicious `Connection` header to start a privilege escalation attack towards the Kubernetes API Server. This vulnerability allows for an exploit of the `cluster-admin` Role bound to `capsule-proxy`. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-0366
Disclosure Date: February 02, 2022 (last updated February 23, 2025)
An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.
0
Attacker Value
Unknown
CVE-2021-25035
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2020-10716
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This flaw affects tfm-rubygem-foreman_ansible versions before 4.0.3.4.
0
Attacker Value
Unknown
CVE-2020-10693
Disclosure Date: May 06, 2020 (last updated February 21, 2025)
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
0
Attacker Value
Unknown
CVE-2020-8771
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
0
Attacker Value
Unknown
CVE-2019-8461
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.
0
Attacker Value
Unknown
CVE-2019-8458
Disclosure Date: June 20, 2019 (last updated November 27, 2024)
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.
0
Attacker Value
Unknown
CVE-2019-8459
Disclosure Date: June 20, 2019 (last updated November 27, 2024)
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
0
Attacker Value
Unknown
CVE-2018-19980
Disclosure Date: December 08, 2018 (last updated November 27, 2024)
Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operating system) via a crafted application that sends data to WifiService.
0