Show filters
127 Total Results
Displaying 41-50 of 127
Sort by:
Attacker Value
Unknown

CVE-2022-34177

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related directory, allowing attackers able to configure Pipelines to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
Attacker Value
Unknown

CVE-2022-1215

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
A format string vulnerability was found in libinput
Attacker Value
Unknown

CVE-2022-1086

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability was found in DolphinPHP up to 1.5.0 and classified as problematic. Affected by this issue is the User Management Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-0347

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2021-46097

Disclosure Date: January 27, 2022 (last updated February 23, 2025)
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log
Attacker Value
Unknown

CVE-2021-43556

Disclosure Date: November 16, 2021 (last updated February 23, 2025)
FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-43554

Disclosure Date: November 16, 2021 (last updated February 23, 2025)
FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-38442

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in a heap-corruption condition. An attacker could leverage this vulnerability to execute code in the context of the current process.
Attacker Value
Unknown

CVE-2021-38430

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files, which could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-38438

Disclosure Date: October 07, 2021 (last updated February 23, 2025)
A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid user opens a malformed project file, which may allow arbitrary code execution.