Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2023-4727
Disclosure Date: June 11, 2024 (last updated November 21, 2024)
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
0
Attacker Value
Unknown
CVE-2024-5045
Disclosure Date: May 17, 2024 (last updated February 11, 2025)
A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264742 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-39058
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-39056
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.
0
Attacker Value
Unknown
CVE-2022-39057
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remote attacker with administrator privilege can exploit this vulnerability to perform arbitrary system command and disrupt service.
0
Attacker Value
Unknown
CVE-2022-39055
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
0
Attacker Value
Unknown
CVE-2022-42067
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
0
Attacker Value
Unknown
CVE-2022-42071
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
0
Attacker Value
Unknown
CVE-2022-42070
Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
0