Show filters
998 Total Results
Displaying 91-100 of 998
Sort by:
Attacker Value
Unknown

CVE-2021-3172

Disclosure Date: February 17, 2023 (last updated October 08, 2023)
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.
Attacker Value
Unknown

CVE-2022-25027

Disclosure Date: January 12, 2023 (last updated October 08, 2023)
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Attacker Value
Unknown

CVE-2022-25026

Disclosure Date: January 12, 2023 (last updated October 08, 2023)
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
Attacker Value
Unknown

CVE-2022-31705

Disclosure Date: December 14, 2022 (last updated October 08, 2023)
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
Attacker Value
Unknown

CVE-2022-38395

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.
Attacker Value
Unknown

CVE-2022-36431

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
Attacker Value
Unknown

CVE-2022-45921

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.
Attacker Value
Unknown

CVE-2022-36179

Disclosure Date: November 22, 2022 (last updated October 08, 2023)
Fusiondirectory 1.3 suffers from Improper Session Handling.
Attacker Value
Unknown

CVE-2022-36180

Disclosure Date: November 22, 2022 (last updated October 08, 2023)
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.
Attacker Value
Unknown

CVE-2022-42341

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.