Show filters
941 Total Results
Displaying 241-250 of 941
Sort by:
Attacker Value
Unknown

CVE-2022-32512

Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code execution when a command which exploits this vulnerability is utilized. Affected Products: CanBRASS (Versions prior to V7.5.1)
Attacker Value
Unknown

CVE-2022-22732

Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
Attacker Value
Unknown

CVE-2016-15002

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack remotely.
Attacker Value
Unknown

CVE-2022-1687

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection
Attacker Value
Unknown

CVE-2022-29440

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion Slider plugin <= 3.3.4 at WordPress.
Attacker Value
Unknown

CVE-2022-30232

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Attacker Value
Unknown

CVE-2022-30238

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Attacker Value
Unknown

CVE-2022-30237

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attacker breaks the encoding. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Attacker Value
Unknown

CVE-2022-30236

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Attacker Value
Unknown

CVE-2022-30235

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses brute force. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)