Show filters
154 Total Results
Displaying 61-70 of 154
Sort by:
Attacker Value
Unknown

CVE-2023-27386

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2015-10065

Disclosure Date: January 17, 2023 (last updated October 20, 2023)
A vulnerability classified as critical was found in AenBleidd FiND. This vulnerability affects the function init_result of the file validator/my_validator.cpp. The manipulation leads to buffer overflow. The patch is identified as ee2eef34a83644f286c9adcaf30437f92e9c48f1. It is recommended to apply a patch to fix this issue. VDB-218458 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-3850

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack
Attacker Value
Unknown

CVE-2022-2311

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.
Attacker Value
Unknown

CVE-2022-38168

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Attacker Value
Unknown

CVE-2022-36878

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.
Attacker Value
Unknown

CVE-2022-33707

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
Attacker Value
Unknown

CVE-2022-1472

Disclosure Date: June 20, 2022 (last updated February 23, 2025)
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
Attacker Value
Unknown

CVE-2022-1749

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.
Attacker Value
Unknown

CVE-2022-30742

Disclosure Date: June 07, 2022 (last updated February 23, 2025)
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.