Show filters
305 Total Results
Displaying 171-180 of 305
Sort by:
Attacker Value
Unknown
CVE-2022-28819
Disclosure Date: May 10, 2022 (last updated February 23, 2025)
Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file.
0
Attacker Value
Unknown
CVE-2022-23705
Disclosure Date: May 09, 2022 (last updated October 07, 2023)
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.
0
Attacker Value
Unknown
CVE-2022-23703
Disclosure Date: April 12, 2022 (last updated October 07, 2023)
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update. This would potentially allow an attacker to intercept and modify network communication for software updates initiated by the Nimble appliance. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 5.0.10.100, 5.2.1.500, 6.0.0.100
0
Attacker Value
Unknown
CVE-2022-0314
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-44906
Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
0
Attacker Value
Unknown
CVE-2022-23602
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview" endpoint. Even if NimForum is running as a non-critical user, the forum.json secrets can be stolen. Version 2.2.0 of NimForum includes patches for this vulnerability. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2021-45097
Disclosure Date: December 16, 2021 (last updated February 23, 2025)
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.
0
Attacker Value
Unknown
CVE-2021-45096
Disclosure Date: December 16, 2021 (last updated February 23, 2025)
KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.
0
Attacker Value
Unknown
CVE-2021-44726
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
0
Attacker Value
Unknown
CVE-2021-44725
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.
0