Show filters
80 Total Results
Displaying 21-30 of 80
Sort by:
Attacker Value
Unknown

CVE-2022-40300

Disclosure Date: September 16, 2022 (last updated January 14, 2025)
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
Attacker Value
Unknown

CVE-2022-27438

Disclosure Date: June 06, 2022 (last updated October 07, 2023)
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
Attacker Value
Unknown

CVE-2022-28394

Disclosure Date: May 27, 2022 (last updated October 07, 2023)
EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).
Attacker Value
Unknown

CVE-2022-30523

Disclosure Date: May 16, 2022 (last updated October 07, 2023)
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege escalation on the affected machine.
Attacker Value
Unknown

CVE-2022-29081

Disclosure Date: April 28, 2022 (last updated January 14, 2025)
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.
Attacker Value
Unknown

CVE-2022-28795

Disclosure Date: April 12, 2022 (last updated October 07, 2023)
A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this information via JavaScript. The issue was fixed with the browser extensions version 2.18.5 for Chrome, MS Edge, Opera, Firefox, and Safari.
Attacker Value
Unknown

CVE-2022-26337

Disclosure Date: March 08, 2022 (last updated October 07, 2023)
Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine.
Attacker Value
Unknown

CVE-2021-35052

Disclosure Date: November 23, 2021 (last updated October 07, 2023)
A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.
Attacker Value
Unknown

CVE-2021-44037

Disclosure Date: November 19, 2021 (last updated October 07, 2023)
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
Attacker Value
Unknown

CVE-2021-44036

Disclosure Date: November 19, 2021 (last updated October 07, 2023)
Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.