Show filters
545 Total Results
Displaying 111-120 of 545
Sort by:
Attacker Value
Unknown

CVE-2022-28229

Disclosure Date: December 23, 2022 (last updated October 08, 2023)
The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions.
Attacker Value
Unknown

CVE-2022-25895

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
Attacker Value
Unknown

CVE-2022-25940

Disclosure Date: December 20, 2022 (last updated February 24, 2025)
All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
Attacker Value
Unknown

CVE-2022-25931

Disclosure Date: December 20, 2022 (last updated February 24, 2025)
All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
Attacker Value
Unknown

CVE-2022-4587

Disclosure Date: December 17, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in Opencaching Deutschland oc-server3. This issue affects some unknown processing of the file htdocs/templates2/ocstyle/login.tpl of the component Login Page. The manipulation of the argument username leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 3296ebd61e7fe49e93b5755d5d7766d6e94a7667. It is recommended to apply a patch to fix this issue. The identifier VDB-216173 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-4586

Disclosure Date: December 17, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic was found in Opencaching Deutschland oc-server3. This vulnerability affects unknown code of the file htdocs/templates2/ocstyle/cachelists.tpl of the component Cachelist Handler. The manipulation of the argument name_filter/by_filter leads to cross site scripting. The attack can be initiated remotely. The name of the patch is a9f79c7da78cd24a7ef1d298e6bc86006972ea73. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216172.
Attacker Value
Unknown

CVE-2022-4585

Disclosure Date: December 17, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in Opencaching Deutschland oc-server3. This affects an unknown part of the file htdocs/templates2/ocstyle/start.tpl of the component Cookie Handler. The manipulation of the argument usercountryCode leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is c720f2777a452186c67ef30db3679dd409556544. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216171.
Attacker Value
Unknown

CVE-2022-25848

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.
Attacker Value
Unknown

CVE-2021-4241

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to the public and may be used. The name of the patch is bb10a5f3c68527c58073258cb12446782d223bc3. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213744.
Attacker Value
Unknown

CVE-2021-4240

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to the public and may be used. The name of the patch is 3daa804d5f56c55b3ae13bfac368bb84ec632193. It is recommended to apply a patch to fix this issue. The identifier VDB-213717 was assigned to this vulnerability.