Latest CVE Feed
-
4.3
MEDIUMCVE-2022-26051
Operation restriction bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Portal.... Read more
Affected Products : garoon- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-0648
Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."... Read more
Affected Products : safehtml- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-25986
Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler.... Read more
Affected Products : office- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-26070
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.... Read more
Affected Products : splunk- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-31178
eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability has been patched in 4.3.4. Users are advised to upgrade... Read more
Affected Products : elabftw- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-29489
Cross-Site Request Forgery (CSRF) vulnerability in Sucuri Security plugin <= 1.8.33 at WordPress leading to Event log entry creation.... Read more
Affected Products : security- Published: Sep. 16, 2022
- Modified: Feb. 19, 2025
-
4.3
MEDIUMCVE-2022-31255
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4... Read more
- Published: Nov. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-30320
Saia Burgess Controls (SBC) PCD through 2022-05-06 uses a Broken or Risky Cryptographic Algorithm. According to FSCT-2022-0063, there is a Saia Burgess Controls (SBC) PCD S-Bus weak credential hashing scheme issue. The affected components are characterize... Read more
Affected Products : saia_pg5_controls_suite- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-26731
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious website may be able to track users in Safari private browsing mode.... Read more
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-2908
A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a specia... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2022-0344
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting from 10.1 before 14.6.4, all versions starting from 10.2 before 14.7.1. Private project paths can be disclosed to unauthorized users via ... Read more
Affected Products : gitlab- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-29612
SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misus... Read more
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-30115
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not usi... Read more
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-4067
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these detail... Read more
- Published: Aug. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-28147
A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.... Read more
Affected Products : continuous_integration_with_toad_edge- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-28137
A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.... Read more
Affected Products : jiratestresultreporter- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-33311
Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Address Book via unspecified vectors.... Read more
Affected Products : office- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-29613
Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on c... Read more
Affected Products : employee_self_service- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-28252
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memo... Read more
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-28269
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of th... Read more
- Published: May. 11, 2022
- Modified: Nov. 21, 2024