Show filters
188 Total Results
Displaying 51-60 of 188
Sort by:
Attacker Value
Unknown

CVE-2023-0277

Disclosure Date: April 17, 2023 (last updated October 08, 2023)
The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
Attacker Value
Unknown

CVE-2022-45155

Disclosure Date: March 02, 2023 (last updated October 08, 2023)
An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the call to the service to delete files and directories on the system of the victim. This issue affects: SUSE openSUSE Factory obs-service-go_modules versions prior to 0.6.1.
Attacker Value
Unknown

CVE-2023-0148

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Gallery Factory Lite WordPress plugin through 2.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-0668

Disclosure Date: January 08, 2023 (last updated October 08, 2023)
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
Attacker Value
Unknown

CVE-2022-38744

Disclosure Date: October 27, 2022 (last updated November 08, 2023)
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.
Attacker Value
Unknown

CVE-2022-31256

Disclosure Date: October 26, 2022 (last updated December 22, 2024)
A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.
Attacker Value
Unknown

CVE-2022-3158

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could allow a user with basic user privileges to perform remote code execution on the server.
Attacker Value
Unknown

CVE-2022-38743

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully exploited, this could allow the attacker to execute arbitrary code and gain access to restricted data.
Attacker Value
Unknown

CVE-2022-39861

Disclosure Date: October 07, 2022 (last updated October 08, 2023)
Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.
Attacker Value
Unknown

CVE-2022-39858

Disclosure Date: October 07, 2022 (last updated October 08, 2023)
Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.