Show filters
501 Total Results
Displaying 151-160 of 501
Sort by:
Attacker Value
Unknown

CVE-2022-34787

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
Attacker Value
Unknown

CVE-2017-20101

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.
Attacker Value
Unknown

CVE-2022-1822

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-30482

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.php via the ctg_name parameters.
Attacker Value
Unknown

CVE-2022-30478

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.
Attacker Value
Unknown

CVE-2021-4225

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.
Attacker Value
Unknown

CVE-2022-26627

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.
Attacker Value
Unknown

CVE-2021-22572

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive information written to theses files is visible to all other local users on unix-like systems. We recommend upgrading past commit https://github.com/google/data-transfer-project/pull/969
Attacker Value
Unknown

CVE-2022-26295

Disclosure Date: March 16, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user name field.
Attacker Value
Unknown

CVE-2022-26293

Disclosure Date: March 16, 2022 (last updated February 23, 2025)
Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.