Show filters
600 Total Results
Displaying 241-250 of 600
Sort by:
Attacker Value
Unknown

CVE-2022-0781

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection
Attacker Value
Unknown

CVE-2022-26865

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator.
Attacker Value
Unknown

CVE-2022-21405

Disclosure Date: April 19, 2022 (last updated November 29, 2024)
Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Oracle Explorer). The supported version that is affected is 18.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where OSS Support Tools executes to compromise OSS Support Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OSS Support Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N).
0
Attacker Value
Unknown

CVE-2022-27852

Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 versions.
Attacker Value
Unknown

CVE-2022-28778

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the arbitrary folder as Secret Folder without Samsung Security Supporter permission
Attacker Value
Unknown

CVE-2022-25373

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
Attacker Value
Unknown

CVE-2022-0322

Disclosure Date: March 25, 2022 (last updated February 23, 2025)
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
Attacker Value
Unknown

CVE-2021-4157

Disclosure Date: March 25, 2022 (last updated February 23, 2025)
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.
Attacker Value
Unknown

CVE-2021-4203

Disclosure Date: March 25, 2022 (last updated February 23, 2025)
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.
Attacker Value
Unknown

CVE-2021-4197

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for cgroup2 and cgroup1 versions of control groups. A local user could use this flaw to crash the system or escalate their privileges on the system.