Show filters
104 Total Results
Displaying 11-20 of 104
Sort by:
Attacker Value
Unknown

CVE-2022-28619

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The vulnerability could allow local escalation of privilege. HPE has made the following software update to resolve the vulnerability in HPE Version Control Repository Manager installer 7.6.14.0.
Attacker Value
Unknown

CVE-2022-26856

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application's database with privileges of the compromised account.
Attacker Value
Unknown

CVE-2022-27907

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
Attacker Value
Unknown

CVE-2021-43961

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
Attacker Value
Unknown

CVE-2020-36518

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Attacker Value
Unknown

CVE-2022-23308

Disclosure Date: February 26, 2022 (last updated February 23, 2025)
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
Attacker Value
Unknown

CVE-2021-45105

Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Attacker Value
Unknown

CVE-2021-43293

Disclosure Date: November 04, 2021 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).
Attacker Value
Unknown

CVE-2021-42568

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.
Attacker Value
Unknown

CVE-2021-40143

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.