Show filters
321 Total Results
Displaying 91-100 of 321
Sort by:
Attacker Value
Unknown
CVE-2022-37679
Disclosure Date: September 02, 2022 (last updated February 24, 2025)
Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Excerpt field.
0
Attacker Value
Unknown
CVE-2022-36601
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2022-34149
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
0
Attacker Value
Unknown
CVE-2022-34858
Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
0
Attacker Value
Unknown
CVE-2022-35919
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.
0
Attacker Value
Unknown
CVE-2016-0796
Disclosure Date: July 28, 2022 (last updated February 24, 2025)
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind vulnerable website or to perform otherwise restricted actions and subsequently download files with the extension mp3, mp4a, wav and ogg from anywhere the web server application has read access to the system. WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files version 1.7.6 is vulnerable; prior versions may also be affected.
0
Attacker Value
Unknown
CVE-2022-2133
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.
0
Attacker Value
Unknown
CVE-2022-30929
Disclosure Date: July 06, 2022 (last updated February 24, 2025)
Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
0
Attacker Value
Unknown
CVE-2022-1995
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-1994
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
0