Show filters
496 Total Results
Displaying 251-260 of 496
Sort by:
Attacker Value
Unknown
CVE-2022-29963
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.
0
Attacker Value
Unknown
CVE-2022-29962
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.
0
Attacker Value
Unknown
CVE-2022-34754
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Link C (A9XELC10-B) (V2.12.0 and prior)
0
Attacker Value
Unknown
CVE-2022-31560
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-34189
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
0
Attacker Value
Unknown
CVE-2017-20087
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.
0
Attacker Value
Unknown
CVE-2022-1961
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
0
Attacker Value
Unknown
CVE-2022-1707
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1.15. The affected file is ~/public/frontend.php and this could be exploited by unauthenticated attackers.
0
Attacker Value
Unknown
CVE-2022-25854
Disclosure Date: April 29, 2022 (last updated February 23, 2025)
This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.
0
Attacker Value
Unknown
CVE-2022-0531
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
0