Show filters
774 Total Results
Displaying 161-170 of 774
Sort by:
Attacker Value
Unknown

CVE-2022-43484

Disclosure Date: December 05, 2022 (last updated February 24, 2025)
TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input validation issue in the binding mechanism of Spring MVC. By the application processing a specially crafted file, arbitrary code may be executed with the privileges of the application.
Attacker Value
Unknown

CVE-2022-38147

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
Attacker Value
Unknown

CVE-2022-37430

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
Attacker Value
Unknown

CVE-2022-38145

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
Attacker Value
Unknown

CVE-2022-37429

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
Attacker Value
Unknown

CVE-2022-38724

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
Attacker Value
Unknown

CVE-2022-38462

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
Attacker Value
Unknown

CVE-2022-38146

Disclosure Date: November 21, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
Attacker Value
Unknown

CVE-2022-38148

Disclosure Date: November 21, 2022 (last updated February 24, 2025)
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
Attacker Value
Unknown

CVE-2022-41064

Disclosure Date: November 09, 2022 (last updated January 11, 2025)
.NET Framework Information Disclosure Vulnerability