Show filters
563 Total Results
Displaying 161-170 of 563
Sort by:
Attacker Value
Unknown

CVE-2022-43999

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.
Attacker Value
Unknown

CVE-2022-44008

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing the back-end Tomcat server directly.
Attacker Value
Unknown

CVE-2022-44007

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.
Attacker Value
Unknown

CVE-2022-36022

Disclosure Date: November 10, 2022 (last updated February 24, 2025)
Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.deeplearning4j:platform-tests through version 1.0.0-M2.1 may use some unclaimed S3 buckets in tests in examples. This is likely affect people who use some older NLP examples that reference an old S3 bucket. The problem has been patched. Users should upgrade to snapshots as Deeplearning4J plan to publish a release with the fix at a later date. As a workaround, download a word2vec google news vector from a new source using git lfs from here.
Attacker Value
Unknown

CVE-2022-39368

Disclosure Date: November 10, 2022 (last updated February 24, 2025)
Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.7.4, Californium is vulnerable to a Denial of Service. Failing handshakes don't cleanup counters for throttling, causing the threshold to be reached without being released again. This results in permanently dropping records. The issue was reported for certificate based handshakes, but may also affect PSK based handshakes. It generally affects client and server as well. This issue is patched in version 3.7.0 and 2.7.4. There are no known workarounds. main: commit 726bac57659410da463dcf404b3e79a7312ac0b9 2.7.x: commit 5648a0c27c2c2667c98419254557a14bac2b1f3f
Attacker Value
Unknown

CVE-2022-3676

Disclosure Date: October 24, 2022 (last updated February 24, 2025)
In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.
Attacker Value
Unknown

CVE-2022-41497

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
Attacker Value
Unknown

CVE-2022-41495

Disclosure Date: October 13, 2022 (last updated February 24, 2025)
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
Attacker Value
Unknown

CVE-2022-3119

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address
Attacker Value
Unknown

CVE-2021-39190

Disclosure Date: September 22, 2022 (last updated February 24, 2025)
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.