Show filters
43 Total Results
Displaying 21-30 of 43
Sort by:
Attacker Value
Unknown

CVE-2024-25995

Disclosure Date: March 12, 2024 (last updated January 30, 2025)
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.
0
Attacker Value
Unknown

CVE-2024-25994

Disclosure Date: March 12, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
0
Attacker Value
Unknown

CVE-2023-35142

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
Attacker Value
Unknown

CVE-2014-125077

Disclosure Date: January 15, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as critical, has been found in pointhi searx_stats. This issue affects some unknown processing of the file cgi/cron.php. The manipulation leads to sql injection. The patch is named 281bd679a4474ddb222d16c1c380f252839cc18f. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218351.
Attacker Value
Unknown

CVE-2022-4522

Disclosure Date: December 15, 2022 (last updated October 08, 2023)
A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is able to address this issue. The name of the patch is e3715b2228ddefe00113296069969f9e184836da. It is recommended to upgrade the affected component. VDB-215902 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-46684

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2022-25201

Disclosure Date: February 15, 2022 (last updated October 25, 2023)
Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-25200

Disclosure Date: February 15, 2022 (last updated October 25, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2019-19677

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
arxes-tolina 3.0.0 allows User Enumeration.
Attacker Value
Unknown

CVE-2019-19676

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.