Show filters
226 Total Results
Displaying 81-90 of 226
Sort by:
Attacker Value
Unknown

CVE-2022-40974

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2022-37409

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Insufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2023-1546

Disclosure Date: May 02, 2023 (last updated October 08, 2023)
The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2023-28725

Disclosure Date: March 22, 2023 (last updated February 24, 2025)
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
Attacker Value
Unknown

CVE-2023-26084

Disclosure Date: March 15, 2023 (last updated February 24, 2025)
The armv8_dec_aes_gcm_full() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. This occurs because of an improperly initialized variable.
Attacker Value
Unknown

CVE-2022-36287

Disclosure Date: February 16, 2023 (last updated February 24, 2025)
Uncaught exception in the FCS Server software maintained by Intel before version 1.1.79.3 may allow a privileged user to potentially enable denial of service via physical access.
Attacker Value
Unknown

CVE-2022-21163

Disclosure Date: February 16, 2023 (last updated February 24, 2025)
Improper access control in the Crypto API Toolkit for Intel(R) SGX before version 2.0 commit ID 91ee496 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-23931

Disclosure Date: February 07, 2023 (last updated February 24, 2025)
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.
Attacker Value
Unknown

CVE-2022-4059

Disclosure Date: January 02, 2023 (last updated February 24, 2025)
The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Attacker Value
Unknown

CVE-2022-44588

Disclosure Date: December 15, 2022 (last updated February 24, 2025)
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.