Show filters
292 Total Results
Displaying 71-80 of 292
Sort by:
Attacker Value
Unknown
CVE-2022-38664
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.
0
Attacker Value
Unknown
CVE-2022-37024
Disclosure Date: August 10, 2022 (last updated October 08, 2023)
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.
0
Attacker Value
Unknown
CVE-2022-36923
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
0
Attacker Value
Unknown
CVE-2022-36887
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.
0
Attacker Value
Unknown
CVE-2022-35404
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
0
Attacker Value
Unknown
CVE-2022-33980
Disclosure Date: July 06, 2022 (last updated November 29, 2024)
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the pr…
0
Attacker Value
Unknown
CVE-2022-34813
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions.
0
Attacker Value
Unknown
CVE-2022-34812
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers to create and delete XPath expressions.
0
Attacker Value
Unknown
CVE-2022-34811
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page.
0
Attacker Value
Unknown
CVE-2022-28621
Disclosure Date: June 28, 2022 (last updated October 07, 2023)
A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. HPE has provided a software update to resolve this vulnerability in HPE NonStop DSM/SCM.
0