Show filters
538 Total Results
Displaying 151-160 of 538
Sort by:
Attacker Value
Unknown

CVE-2022-47506

Disclosure Date: February 15, 2023 (last updated February 24, 2025)
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands.
Attacker Value
Unknown

CVE-2023-22839

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2022-4571

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2014-125067

Disclosure Date: January 08, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in corincerami curiosity. Affected by this vulnerability is an unknown functionality of the file app/controllers/image_controller.rb. The manipulation of the argument sol leads to sql injection. The patch is named d64fddd74ca72714e73f4efe24259ca05c8190eb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217639.
Attacker Value
Unknown

CVE-2022-4114

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-47949

Disclosure Date: December 24, 2022 (last updated February 24, 2025)
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.
Attacker Value
Unknown

CVE-2022-46265

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host header injection vulnerability that could allow an attacker to spoof a Host header information and redirect users to malicious websites.
Attacker Value
Unknown

CVE-2022-44136

Disclosure Date: November 30, 2022 (last updated October 08, 2023)
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
Attacker Value
Unknown

CVE-2022-4231

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214589 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-36964

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.