Show filters
67 Total Results
Displaying 11-20 of 67
Sort by:
Attacker Value
Unknown
CVE-2022-34834
Disclosure Date: October 27, 2023 (last updated November 08, 2023)
An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log.
0
Attacker Value
Unknown
CVE-2022-34833
Disclosure Date: October 27, 2023 (last updated November 08, 2023)
An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component.
0
Attacker Value
Unknown
CVE-2022-34832
Disclosure Date: October 27, 2023 (last updated November 08, 2023)
An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.
0
Attacker Value
Unknown
CVE-2023-35785
Disclosure Date: August 28, 2023 (last updated March 13, 2024)
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 14204 and below and 143xx 14302 and below, ServiceDesk Plus MSP 14300 and below, SharePoint Manager Plus 4402 and below, and Support Center Plus 14300 and below are vulnerable to 2FA bypass via a few TOTP authenticators. Note: A valid pair of username and password is required to leverage this vulnerability.
0
Attacker Value
Unknown
CVE-2023-30565
Disclosure Date: July 13, 2023 (last updated October 08, 2023)
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
0
Attacker Value
Unknown
CVE-2023-31123
Disclosure Date: May 08, 2023 (last updated October 08, 2023)
`effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b, any user with an account on an instance of `effectindex/tripreporter`, e.g. `subjective.report`, may be affected by an improper password verification vulnerability. The vulnerability allows any user with a password matching the password requirements to log in as any user. This allows access to accounts / data loss of the user. This issue is patched in commit bd80ba833b9023d39ca22e29874296c8729dd53b. No action necessary for users of `subjective.report`, and anyone running their own instance should update to this commit or newer as soon as possible. As a workaround, someone running their own instance may apply the patch manually.
0
Attacker Value
Unknown
CVE-2022-4942
Disclosure Date: April 20, 2023 (last updated October 20, 2023)
A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by this issue is the function renderIssue in the library lib/template-generator.js. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The patch is identified as 505c190efd4905990db6207863bdcbd9b1d7e1bd. It is recommended to apply a patch to fix this issue. VDB-226310 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-22624
Disclosure Date: January 17, 2023 (last updated October 08, 2023)
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
0
Attacker Value
Unknown
CVE-2015-10035
Disclosure Date: January 09, 2023 (last updated October 20, 2023)
A vulnerability was found in gperson angular-test-reporter and classified as critical. This issue affects the function getProjectTables/addTest of the file rest-server/data-server.js. The manipulation leads to sql injection. The patch is named a29d8ae121b46ebfa96a55a9106466ab2ef166ae. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217715.
0
Attacker Value
Unknown
CVE-2022-29457
Disclosure Date: April 18, 2022 (last updated October 07, 2023)
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
0