Show filters
541 Total Results
Displaying 141-150 of 541
Sort by:
Attacker Value
Unknown

CVE-2022-41514

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_loan.
Attacker Value
Unknown

CVE-2022-31155

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’ saved searches, only overwriting them with attacker-controlled searches. The issue is patched in Sourcegraph version 3.41.0. There is no workaround for this issue and updating to a secure version is highly recommended.
Attacker Value
Unknown

CVE-2022-31154

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to edit the Code Monitors owned by any other Sourcegraph user. This includes being able to edit both the trigger and the action of the monitor in question. An attacker is not able to read contents of existing code monitors, only override the data. The issue is fixed in Sourcegraph 3.42. There are no workaround for the issue and patching is highly recommended.
Attacker Value
Unknown

CVE-2022-1585

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php.
Attacker Value
Unknown

CVE-2022-34578

Disclosure Date: July 28, 2022 (last updated February 24, 2025)
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
Attacker Value
Unknown

CVE-2022-36896

Disclosure Date: July 27, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-34966

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.
Attacker Value
Unknown

CVE-2022-34962

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.
Attacker Value
Unknown

CVE-2022-34965

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior of the application as it only allows authenticated admins to upload files.
Attacker Value
Unknown

CVE-2022-34964

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module.