Show filters
165 Total Results
Displaying 41-50 of 165
Sort by:
Attacker Value
Unknown

CVE-2022-4790

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Attacker Value
Unknown

CVE-2022-45392

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-38666

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.
Attacker Value
Unknown

CVE-2022-45391

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
Attacker Value
Unknown

CVE-2022-41229

Disclosure Date: September 21, 2022 (last updated February 24, 2025)
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Attacker Value
Unknown

CVE-2022-41228

Disclosure Date: September 21, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.
Attacker Value
Unknown

CVE-2022-41227

Disclosure Date: September 21, 2022 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.
Attacker Value
Unknown

CVE-2021-46827

Disclosure Date: July 13, 2022 (last updated February 24, 2025)
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.
Attacker Value
Unknown

CVE-2021-39019

Disclosure Date: July 13, 2022 (last updated February 24, 2025)
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728.
Attacker Value
Unknown

CVE-2021-39028

Disclosure Date: July 13, 2022 (last updated February 24, 2025)
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 213866.