Show filters
978 Total Results
Displaying 221-230 of 978
Sort by:
Attacker Value
Unknown

CVE-2021-40386

Disclosure Date: April 15, 2022 (last updated October 07, 2023)
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-0531

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2022-27844

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70
Attacker Value
Unknown

CVE-2022-26504

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe
Attacker Value
Unknown

CVE-2022-26501

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Attacker Value
Unknown

CVE-2022-26500

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
Attacker Value
Unknown

CVE-2021-24994

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2022-0255

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue
Attacker Value
Unknown

CVE-2021-33068

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access.
Attacker Value
Unknown

CVE-2021-0156

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.