Show filters
233 Total Results
Displaying 121-130 of 233
Sort by:
Attacker Value
Unknown
CVE-2022-2801
Disclosure Date: August 12, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206247.
0
Attacker Value
Unknown
CVE-2022-1710
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
0
Attacker Value
Unknown
CVE-2022-30770
Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials.
0
Attacker Value
Unknown
CVE-2021-27430
Disclosure Date: March 23, 2022 (last updated February 23, 2025)
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
0
Attacker Value
Unknown
CVE-2022-25190
Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2021-25004
Disclosure Date: February 07, 2022 (last updated February 23, 2025)
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.
0
Attacker Value
Unknown
CVE-2021-25005
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2022-23117
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
0
Attacker Value
Unknown
CVE-2022-23116
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.
0
Attacker Value
Unknown
CVE-2021-42546
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
0