Show filters
95 Total Results
Displaying 31-40 of 95
Sort by:
Attacker Value
Unknown

CVE-2022-4507

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
Attacker Value
Unknown

CVE-2022-29805

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
Attacker Value
Unknown

CVE-2022-31463

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used.
Attacker Value
Unknown

CVE-2022-31462

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.
Attacker Value
Unknown

CVE-2022-31461

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message.
Attacker Value
Unknown

CVE-2022-31460

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value.
Attacker Value
Unknown

CVE-2022-31459

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.
Attacker Value
Unknown

CVE-2022-26616

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
Attacker Value
Unknown

CVE-2022-24181

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
Attacker Value
Unknown

CVE-2022-0445

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack