Show filters
440 Total Results
Displaying 241-250 of 440
Sort by:
Attacker Value
Unknown
CVE-2022-1903
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username
0
Attacker Value
Unknown
CVE-2022-30887
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
0
Attacker Value
Unknown
CVE-2022-28350
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.
0
Attacker Value
Unknown
CVE-2022-28349
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.
0
Attacker Value
Unknown
CVE-2022-28348
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.
0
Attacker Value
Unknown
CVE-2022-30407
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
0
Attacker Value
Unknown
CVE-2022-29180
Disclosure Date: May 07, 2022 (last updated February 23, 2025)
A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. This has been patched and is available in release [v0.12.1](https://github.com/charmbracelet/charm/releases/tag/v0.12.1). We recommend that all users running self-hosted `charm` instances update immediately. This vulnerability was found in-house and we haven't been notified of any potential exploiters. ### Additional notes * Encrypted user data uploaded to the Charm server is safe as Charm servers cannot decrypt user data. This includes filenames, paths, and all key-value data. * Users running the official Charm [Docker images](https://github.com/charmbracelet/charm/blob/main/docker.md) are at minimal risk because the exploit is limited to the containerized filesystem.
0
Attacker Value
Unknown
CVE-2022-28099
Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.
0
Attacker Value
Unknown
CVE-2021-27435
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
0
Attacker Value
Unknown
CVE-2021-27433
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
0