โผ CVE-2022-38137 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-27914 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-43481 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Coupons for WooCommerce Coupons plugin <= 4.5 on WordPress leading to notice dismissal.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32776 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads รขโฌโ Ad Manager & AdSense plugin <= 1.31.1 on WordPress.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41136 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-33322 โผ
๐ Read
via "National Vulnerability Database".
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-40632 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-27858 โผ
๐ Read
via "National Vulnerability Database".
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-40128 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress leading to export file download.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41208 โผ
๐ Read
via "National Vulnerability Database".
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-20446 โผ
๐ Read
via "National Vulnerability Database".
In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-229793943๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41207 โผ
๐ Read
via "National Vulnerability Database".
SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or modification of the victim's information.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41258 โผ
๐ Read
via "National Vulnerability Database".
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality, integrity and availability of the application.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-20447 โผ
๐ Read
via "National Vulnerability Database".
In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233604485๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41205 โผ
๐ Read
via "National Vulnerability Database".
SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-34823 โผ
๐ Read
via "National Vulnerability Database".
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated attacker to overwrite existing files on the file system and to potentially execute arbitrary code.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41211 โผ
๐ Read
via "National Vulnerability Database".
Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer, Arbitrary Code Execution can be triggered when payload forces:Re-use of dangling pointer which refers to overwritten space in memory. The accessed memory must be filled with code to execute the attack. Therefore, repeated success is unlikely.Stack-based buffer overflow. Since the memory overwritten is random, based on access rights of the memory, repeated success is not assured.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32602 โผ
๐ Read
via "National Vulnerability Database".
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388790; Issue ID: ALPS07388790.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41212 โผ
๐ Read
via "National Vulnerability Database".
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a remote enabled function to read a file which is otherwise restricted. On successful exploitation an attacker can completely compromise the confidentiality of the application.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-20448 โผ
๐ Read
via "National Vulnerability Database".
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-237540408๐ Read
via "National Vulnerability Database".
โผ CVE-2022-41259 โผ
๐ Read
via "National Vulnerability Database".
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.๐ Read
via "National Vulnerability Database".