Show filters
501 Total Results
Displaying 151-160 of 501
Sort by:
Attacker Value
Unknown
CVE-2022-34787
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
0
Attacker Value
Unknown
CVE-2017-20101
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.
0
Attacker Value
Unknown
CVE-2022-1822
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parameter in versions up to, and including, 3.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-30482
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.php via the ctg_name parameters.
0
Attacker Value
Unknown
CVE-2022-30478
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.
0
Attacker Value
Unknown
CVE-2021-4225
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.
0
Attacker Value
Unknown
CVE-2022-26627
Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.
0
Attacker Value
Unknown
CVE-2021-22572
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive information written to theses files is visible to all other local users on unix-like systems. We recommend upgrading past commit https://github.com/google/data-transfer-project/pull/969
0
Attacker Value
Unknown
CVE-2022-26295
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user name field.
0
Attacker Value
Unknown
CVE-2022-26293
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.
0