Show filters
796 Total Results
Displaying 261-270 of 796
Sort by:
Attacker Value
Unknown

CVE-2022-27495

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Attacker Value
Unknown

CVE-2022-28792

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.
Attacker Value
Unknown

CVE-2021-25746

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Attacker Value
Unknown

CVE-2021-25745

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Attacker Value
Unknown

CVE-2021-23055

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2022-28379

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
Attacker Value
Unknown

CVE-2022-26268

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.
Attacker Value
Unknown

CVE-2021-3618

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Attacker Value
Unknown

CVE-2021-43737

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.
Attacker Value
Unknown

CVE-2021-43738

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.