Show filters
121 Total Results
Displaying 71-80 of 121
Sort by:
Attacker Value
Unknown
CVE-2022-38878
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
0
Attacker Value
Unknown
CVE-2022-38833
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
0
Attacker Value
Unknown
CVE-2022-38832
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
0
Attacker Value
Unknown
CVE-2022-38269
Disclosure Date: September 08, 2022 (last updated February 24, 2025)
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=.
0
Attacker Value
Unknown
CVE-2022-38268
Disclosure Date: September 08, 2022 (last updated February 24, 2025)
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=.
0
Attacker Value
Unknown
CVE-2022-38267
Disclosure Date: September 08, 2022 (last updated February 24, 2025)
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=.
0
Attacker Value
Unknown
CVE-2022-2429
Disclosure Date: September 06, 2022 (last updated February 24, 2025)
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
0
Attacker Value
Unknown
CVE-2022-29476
Disclosure Date: August 12, 2022 (last updated February 24, 2025)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in 8 Degree Themes otification Bar for WordPress plugin <= 1.1.8 at WordPress.
0
Attacker Value
Unknown
CVE-2022-34801
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
0
Attacker Value
Unknown
CVE-2022-34800
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
0