Show filters
92 Total Results
Displaying 21-30 of 92
Sort by:
Attacker Value
Unknown

CVE-2022-3694

Disclosure Date: December 05, 2022 (last updated October 08, 2023)
The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator's account.
Attacker Value
Unknown

CVE-2022-36536

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
Attacker Value
Unknown

CVE-2022-36534

Disclosure Date: September 16, 2022 (last updated October 08, 2023)
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
Attacker Value
Unknown

CVE-2022-36533

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2022-38400

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a specially crafted URL.
Attacker Value
Unknown

CVE-2022-25304

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.
Attacker Value
Unknown

CVE-2021-46827

Disclosure Date: July 13, 2022 (last updated February 24, 2025)
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.
Attacker Value
Unknown

CVE-2022-31536

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-1712

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Attacker Value
Unknown

CVE-2021-43138

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.