Show filters
440 Total Results
Displaying 131-140 of 440
Sort by:
Attacker Value
Unknown

CVE-2022-28771

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.
Attacker Value
Unknown

CVE-2022-31580

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-31571

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-31520

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-32549

Disclosure Date: June 22, 2022 (last updated February 23, 2025)
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
Attacker Value
Unknown

CVE-2022-29014

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.
Attacker Value
Unknown

CVE-2022-29013

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.
Attacker Value
Unknown

CVE-2022-31313

Disclosure Date: June 08, 2022 (last updated October 07, 2023)
api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package.
Attacker Value
Unknown

CVE-2022-29453

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
Attacker Value
Unknown

CVE-2022-30782

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.