Show filters
461 Total Results
Displaying 111-120 of 461
Sort by:
Attacker Value
Unknown

CVE-2022-2523

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.
Attacker Value
Unknown

CVE-2022-2514

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.
Attacker Value
Unknown

CVE-2021-40660

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack.
Attacker Value
Unknown

CVE-2022-29296

Disclosure Date: June 06, 2022 (last updated February 23, 2025)
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2022-29249

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of security are required. This issue ONLY affects v1.6 and does not affect anything pre-1.6. The vulnerability has been patched in release 1.7. Currently, there is no way to fix the issue without upgrading.
Attacker Value
Unknown

CVE-2022-28965

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before v21.11.2500 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted DLL file.
Attacker Value
Unknown

CVE-2022-28964

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attackers to cause a Denial of Service (DoS) via a crafted DLL file.
Attacker Value
Unknown

CVE-2022-1279

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-client versions prior to 1.2.
Attacker Value
Unknown

CVE-2021-46030

Disclosure Date: January 19, 2022 (last updated February 23, 2025)
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.
Attacker Value
Unknown

CVE-2021-45339

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense.