Show filters
89 Total Results
Displaying 31-40 of 89
Sort by:
Attacker Value
Unknown
CVE-2022-44380
Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
0
Attacker Value
Unknown
CVE-2022-3173
Disclosure Date: September 17, 2022 (last updated October 08, 2023)
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
0
Attacker Value
Unknown
CVE-2022-3035
Disclosure Date: August 29, 2022 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
0
Attacker Value
Unknown
CVE-2022-2997
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
0
Attacker Value
Unknown
CVE-2022-32061
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
0
Attacker Value
Unknown
CVE-2022-32060
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
0
Attacker Value
Unknown
CVE-2022-27438
Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected installation to trigger the update check.
0
Attacker Value
Unknown
CVE-2022-25617
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerable parameter.
0
Attacker Value
Unknown
CVE-2022-29435
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress allows an attacker to delete or to turn on/off snippets.
0
Attacker Value
Unknown
CVE-2022-29436
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).
0