Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown

CVE-2023-23169

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.
Attacker Value
Unknown

CVE-2022-26486

Disclosure Date: December 22, 2022 (last updated October 08, 2023)
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Attacker Value
Unknown

CVE-2022-26485

Disclosure Date: December 22, 2022 (last updated October 08, 2023)
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Attacker Value
Unknown

CVE-2022-3462

Disclosure Date: November 07, 2022 (last updated December 22, 2024)
The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2022-36344

Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.
Attacker Value
Unknown

CVE-2022-27657

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by exploiting insufficient validation of path information in SAP Focused Run (Simple Diagnostics Agent 1.0) - version 1.0.
Attacker Value
Unknown

CVE-2022-24399

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipart/form-data, resulting in Cross-Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2021-3793

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware.
Attacker Value
Unknown

CVE-2021-3792

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker.
Attacker Value
Unknown

CVE-2021-3791

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password.