Search Results (347158 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-23109 1 Jenkins 1 Hashicorp Vault 2024-11-21 6.5 Medium
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.
CVE-2022-23108 1 Jenkins 1 Badge 2024-11-21 5.4 Medium
Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2022-23107 1 Jenkins 1 Warnings Next Generation 2024-11-21 8.1 High
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.
CVE-2022-23106 1 Jenkins 1 Configuration As Code 2024-11-21 5.3 Medium
Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.
CVE-2022-23105 1 Jenkins 1 Active Directory 2024-11-21 6.5 Medium
Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.
CVE-2022-23102 1 Siemens 1 Sinema Remote Connect Server 2024-11-21 6.1 Medium
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
CVE-2022-23101 1 Open-xchange 1 Ox App Suite 2024-11-21 6.1 Medium
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
CVE-2022-23100 1 Open-xchange 1 Ox App Suite 2024-11-21 9.8 Critical
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
CVE-2022-23099 1 Open-xchange 1 App Suite 2024-11-21 5.4 Medium
OX App Suite through 7.10.6 allows XSS by forcing block-wise read.
CVE-2022-23098 2 Debian, Intel 2 Debian Linux, Connman 2024-11-21 7.5 High
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.
CVE-2022-23097 2 Debian, Intel 2 Debian Linux, Connman 2024-11-21 9.1 Critical
An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.
CVE-2022-23096 2 Debian, Intel 2 Debian Linux, Connman 2024-11-21 9.1 Critical
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.
CVE-2022-23094 4 Debian, Fedoraproject, Libreswan and 1 more 5 Debian Linux, Fedora, Libreswan and 2 more 2024-11-21 7.5 High
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
CVE-2022-23083 1 Broadcom 2 Netmaster File Transfer Management, Netmaster Network Management For Tcp\/ip 2024-11-21 6.1 Medium
NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.
CVE-2022-23082 1 Mend 1 Curekit 2024-11-21 7.5 High
In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.
CVE-2022-23081 1 Openlibrary 1 Openlibrary 2024-11-21 N/A
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.
CVE-2022-23080 1 Rangerstudio 1 Directus 2024-11-21 5.0 Medium
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.
CVE-2022-23079 1 Getmotoradmin 1 Motor Admin 2024-11-21 N/A
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
CVE-2022-23078 1 Habitica 1 Habitica 2024-11-21 N/A
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
CVE-2022-23077 1 Habitica 1 Habitica 2024-11-21 6.1 Medium
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.