Show filters
275 Total Results
Displaying 121-130 of 275
Sort by:
Attacker Value
Unknown
CVE-2022-35275
Disclosure Date: August 25, 2022 (last updated February 24, 2025)
Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For WooCommerce plugin <= 3.3.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-31567
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-31566
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-35412
Disclosure Date: July 08, 2022 (last updated October 07, 2023)
Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the product) to disable some of the agent functionality and then exfiltrate files to an external USB device.
0
Attacker Value
Unknown
CVE-2022-31887
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.
0
Attacker Value
Unknown
CVE-2022-31884
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys including high privilege and the Administrator users API Keys.
0
Attacker Value
Unknown
CVE-2022-31886
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
0
Attacker Value
Unknown
CVE-2022-31885
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
0
Attacker Value
Unknown
CVE-2022-31883
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.
0
Attacker Value
Unknown
CVE-2022-31395
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua.
0