Show filters
231 Total Results
Displaying 121-130 of 231
Sort by:
Attacker Value
Unknown

CVE-2022-40136

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-40135

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-40134

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-4789

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The WPZOOM Portfolio WordPress plugin before 1.2.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Attacker Value
Unknown

CVE-2022-4578

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-36928

Disclosure Date: January 06, 2023 (last updated February 24, 2025)
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.
Attacker Value
Unknown

CVE-2022-28761

Disclosure Date: October 11, 2022 (last updated February 24, 2025)
Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.
Attacker Value
Unknown

CVE-2022-40925

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.
Attacker Value
Unknown

CVE-2022-40924

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
Attacker Value
Unknown

CVE-2022-40932

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.