Show filters
732 Total Results
Displaying 231-240 of 732
Sort by:
Attacker Value
Unknown

CVE-2022-25887

Disclosure Date: August 30, 2022 (last updated February 24, 2025)
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
Attacker Value
Unknown

CVE-2022-37418

Disclosure Date: August 24, 2022 (last updated February 24, 2025)
The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote attackers to perform unlock operations and force a resynchronization after capturing two consecutive valid key fob signals over the radio, aka a RollBack attack. The attacker retains the ability to unlock indefinitely.
Attacker Value
Unknown

CVE-2022-38463

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
Attacker Value
Unknown

CVE-2022-38172

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.
Attacker Value
Unknown

CVE-2022-2272

Disclosure Date: August 03, 2022 (last updated February 24, 2025)
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of calls to the login endpoint. When parsing the username element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17331.
Attacker Value
Unknown

CVE-2022-35920

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.
Attacker Value
Unknown

CVE-2022-36879

Disclosure Date: July 27, 2022 (last updated February 24, 2025)
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
Attacker Value
Unknown

CVE-2022-31103

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended on by [react-letter](https://github.com/mat-sz/react-letter), therefore everyone using react-letter is also at risk. The problem has been patched in version 1.0.2.
Attacker Value
Unknown

CVE-2022-28168

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored using Base64 encoding, which could allow an attacker able to access log files to easily decode the passwords.
Attacker Value
Unknown

CVE-2022-28167

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log