Show filters
501 Total Results
Displaying 81-90 of 501
Sort by:
Attacker Value
Unknown
CVE-2022-26135
Disclosure Date: June 29, 2022 (last updated February 24, 2025)
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.
0
Attacker Value
Unknown
CVE-2022-23171
Disclosure Date: June 20, 2022 (last updated October 07, 2023)
AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed.
0
Attacker Value
Unknown
CVE-2022-29597
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of the internal system file requested. This ability could allow for adversaries to extract sensitive data and/or files from the underlying file system, gain knowledge about the internal workings of the system, or access source code of the application.
0
Attacker Value
Unknown
CVE-2022-29598
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .
0
Attacker Value
Unknown
CVE-2022-29452
Disclosure Date: May 27, 2022 (last updated February 23, 2025)
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-1104
Disclosure Date: May 09, 2022 (last updated February 23, 2025)
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2022-0914
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example
0
Attacker Value
Unknown
CVE-2022-0892
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-26133
Disclosure Date: March 24, 2022 (last updated February 23, 2025)
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
0
Attacker Value
Unknown
CVE-2021-43955
Disclosure Date: March 14, 2022 (last updated October 07, 2023)
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.
0