Show filters
200 Total Results
Displaying 61-70 of 200
Sort by:
Attacker Value
Unknown

CVE-2022-47141

Disclosure Date: March 14, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions.
Attacker Value
Unknown

CVE-2022-3767

Disclosure Date: March 09, 2023 (last updated October 08, 2023)
Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.
Attacker Value
Unknown

CVE-2022-4317

Disclosure Date: March 09, 2023 (last updated October 08, 2023)
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
Attacker Value
Unknown

CVE-2022-4315

Disclosure Date: March 08, 2023 (last updated October 08, 2023)
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
Attacker Value
Unknown

CVE-2023-1113

Disclosure Date: March 01, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=admin of the component POST Parameter Handler. The manipulation of the argument fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222073 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-46956

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.
Attacker Value
Unknown

CVE-2022-46955

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_queue.
Attacker Value
Unknown

CVE-2022-46954

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_transaction.
Attacker Value
Unknown

CVE-2022-46953

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_window.
Attacker Value
Unknown

CVE-2022-46952

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_user.