Show filters
440 Total Results
Displaying 121-130 of 440
Sort by:
Attacker Value
Unknown
CVE-2022-3691
Disclosure Date: November 21, 2022 (last updated February 24, 2025)
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
0
Attacker Value
Unknown
CVE-2022-45146
Disclosure Date: November 21, 2022 (last updated February 24, 2025)
An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11.
0
Attacker Value
Unknown
CVE-2022-45073
Disclosure Date: November 09, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.
0
Attacker Value
Unknown
CVE-2022-1414
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access to sensitive information or conduct further attacks.
0
Attacker Value
Unknown
CVE-2019-25075
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
0
Attacker Value
Unknown
CVE-2021-3442
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vulnerability is to data confidentiality.
0
Attacker Value
Unknown
CVE-2022-26844
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-26374
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Uncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-26344
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2022-36900
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
0