Show filters
275 Total Results
Displaying 121-130 of 275
Sort by:
Attacker Value
Unknown

CVE-2022-35275

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.
Attacker Value
Unknown

CVE-2022-31567

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-31566

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-35412

Disclosure Date: July 08, 2022 (last updated October 07, 2023)
Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the product) to disable some of the agent functionality and then exfiltrate files to an external USB device.
Attacker Value
Unknown

CVE-2022-31887

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.
Attacker Value
Unknown

CVE-2022-31884

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
Attacker Value
Unknown

CVE-2022-31886

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
Attacker Value
Unknown

CVE-2022-31885

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
Attacker Value
Unknown

CVE-2022-31883

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.
Attacker Value
Unknown

CVE-2022-31395

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua.