Show filters
323 Total Results
Displaying 81-90 of 323
Sort by:
Attacker Value
Unknown

CVE-2022-3768

Disclosure Date: November 28, 2022 (last updated February 24, 2025)
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
Attacker Value
Unknown

CVE-2022-37164

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.
Attacker Value
Unknown

CVE-2022-37146

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their authentication provider take significantly longer than those for invalid users, allowing for valid users to be enumerated by an unauthenticated remote attacker. Note that the lockout policy implemented in Plextrac version 1.17.0 makes it impossible to distinguish between valid, locked user accounts and user accounts that do not exist, but does not prevent valid, unlocked users from being enumerated.
Attacker Value
Unknown

CVE-2022-37145

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.
Attacker Value
Unknown

CVE-2022-37144

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections to login as the targeted user.
Attacker Value
Unknown

CVE-2022-35198

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
Attacker Value
Unknown

CVE-2022-34927

Disclosure Date: August 03, 2022 (last updated February 24, 2025)
MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is triggered when the program is supplied a crafted XM module file.
Attacker Value
Unknown

CVE-2022-32323

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
Attacker Value
Unknown

CVE-2022-33043

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers to execute arbitrary web scripts or HTML via a crafted excel file.
Attacker Value
Unknown

CVE-2021-43308

Disclosure Date: May 29, 2022 (last updated February 23, 2025)
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function