Show filters
977 Total Results
Displaying 181-190 of 977
Sort by:
Attacker Value
Unknown
CVE-2022-38079
Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability Backup Scheduler plugin <= 1.5.13 at WordPress.
0
Attacker Value
Unknown
CVE-2022-37027
Disclosure Date: September 21, 2022 (last updated February 24, 2025)
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.
0
Attacker Value
Unknown
CVE-2022-2863
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack
0
Attacker Value
Unknown
CVE-2022-36617
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.
0
Attacker Value
Unknown
CVE-2022-2442
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
0
Attacker Value
Unknown
CVE-2022-2271
Disclosure Date: September 05, 2022 (last updated February 24, 2025)
The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-35866
Disclosure Date: August 03, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The server uses a hard-coded password for the administrator user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17139.
0
Attacker Value
Unknown
CVE-2022-37000
Disclosure Date: July 28, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
0
Attacker Value
Unknown
CVE-2022-36999
Disclosure Date: July 28, 2022 (last updated October 08, 2023)
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
0
Attacker Value
Unknown
CVE-2022-36998
Disclosure Date: July 28, 2022 (last updated February 24, 2025)
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary server, resulting in a denial of service.
0