Show filters
203 Total Results
Displaying 101-110 of 203
Sort by:
Attacker Value
Unknown

CVE-2023-0676

Disclosure Date: February 04, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
Attacker Value
Unknown

CVE-2022-4394

Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2022-4392

Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2022-36943

Disclosure Date: January 03, 2023 (last updated February 24, 2025)
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
Attacker Value
Unknown

CVE-2022-4595

Disclosure Date: December 18, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in django-openipam. This affects an unknown part of the file openipam/report/templates/report/exposed_hosts.html. The manipulation of the argument description leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is a6223a1150d60cd036106ba6a8e676c1bfc3cc85. It is recommended to apply a patch to fix this issue. The identifier VDB-216189 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-3845

Disclosure Date: November 02, 2022 (last updated February 24, 2025)
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.0 is able to address this issue. The name of the patch is 22c797c3583001211fe7d31bccd3f1d4aeeb3bbc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-212863.
Attacker Value
Unknown

CVE-2022-41443

Disclosure Date: October 03, 2022 (last updated February 24, 2025)
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
Attacker Value
Unknown

CVE-2021-41714

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.
Attacker Value
Unknown

CVE-2022-29623

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
An arbitrary file upload vulnerability in the file upload module of Connect-Multiparty v2.2.0 allows attackers to execute arbitrary code via a crafted PDF file.
Attacker Value
Unknown

CVE-2022-1225

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.