Show filters
156 Total Results
Displaying 11-20 of 156
Sort by:
Attacker Value
Unknown
CVE-2021-45466
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.
0
Attacker Value
Unknown
CVE-2022-36357
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
0
Attacker Value
Unknown
CVE-2022-37603
Disclosure Date: October 14, 2022 (last updated February 24, 2025)
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
0
Attacker Value
Unknown
CVE-2022-37601
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
0
Attacker Value
Unknown
CVE-2022-37599
Disclosure Date: October 11, 2022 (last updated February 24, 2025)
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
0
Attacker Value
Unknown
CVE-2022-36285
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-34648
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-36752
Disclosure Date: July 28, 2022 (last updated February 24, 2025)
png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable via a crafted png file.
0
Attacker Value
Unknown
CVE-2022-25048
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
0
Attacker Value
Unknown
CVE-2022-25047
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
0