Show filters
461 Total Results
Displaying 221-230 of 461
Sort by:
Attacker Value
Unknown
CVE-2022-28109
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is: Triggered by browsing to to a malicious remote web server. The WebDriver endpoint of Selenium Server (Grid) is vulnerable to DNS rebinding. This can be used to execute arbitrary code on the machine.
0
Attacker Value
Unknown
CVE-2022-0447
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-25090
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisation and escaping, it could also allows attackers to perform Cross-Site Scripting attacks on pages where a Portfolio is embed
0
Attacker Value
Unknown
CVE-2021-24986
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in pages containing a Post Grid with a search form
0
Attacker Value
Unknown
CVE-2022-23233
Disclosure Date: March 04, 2022 (last updated October 07, 2023)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS) of the Local Distribution Router (LDR) service.
0
Attacker Value
Unknown
CVE-2022-23232
Disclosure Date: March 04, 2022 (last updated October 07, 2023)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user accounts to access S3 data to which they previously had access. StorageGRID 11.6.0 obtains the user account status from Active Directory or Azure and will block S3 access for disabled user accounts during the subsequent background synchronization. User accounts that are expired or locked for Active Directory or Azure, or user accounts that are disabled, expired, or locked in identity sources other than Active Directory or Azure must be manually removed from group memberships or have their S3 keys manually removed from Tenant Manager in all versions of StorageGRID (formerly StorageGRID Webscale).
0
Attacker Value
Unknown
CVE-2022-0186
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard
0
Attacker Value
Unknown
CVE-2022-23773
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
0
Attacker Value
Unknown
CVE-2022-23772
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
0
Attacker Value
Unknown
CVE-2022-0233
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7.
0