Show filters
809 Total Results
Displaying 201-210 of 809
Sort by:
Attacker Value
Unknown
CVE-2022-39182
Disclosure Date: January 12, 2023 (last updated October 08, 2023)
H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain system privileges.
0
Attacker Value
Unknown
CVE-2022-3855
Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2022-3679
Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
0
Attacker Value
Unknown
CVE-2020-36566
Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
0
Attacker Value
Unknown
CVE-2022-4582
Disclosure Date: December 17, 2022 (last updated February 24, 2025)
A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.6.11 is able to address this issue. The name of the patch is 2606983c20f6ea3430ac4b36b3d2e88aafef45da. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216168.
0
Attacker Value
Unknown
CVE-2022-43517
Disclosure Date: December 13, 2022 (last updated February 24, 2025)
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders.
This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges.
0
Attacker Value
Unknown
CVE-2022-1038
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.
0
Attacker Value
Unknown
CVE-2022-44962
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field.
0
Attacker Value
Unknown
CVE-2022-44961
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
0
Attacker Value
Unknown
CVE-2022-44960
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.
0