Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2023-4727

Disclosure Date: June 11, 2024 (last updated November 21, 2024)
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
0
Attacker Value
Unknown

CVE-2024-5045

Disclosure Date: May 17, 2024 (last updated February 11, 2025)
A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264742 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-39058

Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
Attacker Value
Unknown

CVE-2022-39056

Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.
Attacker Value
Unknown

CVE-2022-39057

Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system command and disrupt service.
Attacker Value
Unknown

CVE-2022-39055

Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
Attacker Value
Unknown

CVE-2022-42067

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
Attacker Value
Unknown

CVE-2022-42071

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
Attacker Value
Unknown

CVE-2022-42070

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).