Show filters
545 Total Results
Displaying 131-140 of 545
Sort by:
Attacker Value
Unknown
CVE-2022-31527
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2021-40668
Disclosure Date: June 09, 2022 (last updated February 23, 2025)
The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.
0
Attacker Value
Unknown
CVE-2022-29718
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
0
Attacker Value
Unknown
CVE-2022-31013
Disclosure Date: May 31, 2022 (last updated February 23, 2025)
Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an async function, as the code is not using `await` to wait for the verification result. Every time the function responds back with success, along with an unhandled exception if the token is invalid. A patch is available in version 2.6.0.
0
Attacker Value
Unknown
CVE-2021-33318
Disclosure Date: May 16, 2022 (last updated February 23, 2025)
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP addresses and subnets.
0
Attacker Value
Unknown
CVE-2021-28290
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
0
Attacker Value
Unknown
CVE-2022-28480
Disclosure Date: April 29, 2022 (last updated February 23, 2025)
ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.
0
Attacker Value
Unknown
CVE-2022-29589
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.
0
Attacker Value
Unknown
CVE-2022-24846
Disclosure Date: April 14, 2022 (last updated February 23, 2025)
GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code execution. While in GeoWebCache the JNDI strings are provided via local configuration file, in GeoServer a user interface is provided to perform the same, that can be accessed remotely, and requires admin-level login to be used. These lookup are unrestricted in scope and can lead to code execution. The lookups are going to be restricted in GeoWebCache 1.21.0, 1.20.2, 1.19.3.
0
Attacker Value
Unknown
CVE-2021-43462
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
0