• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-44725
2022-11-22
N/A
7.8 HIGH
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).
CVE-2022-44724
2023-02-03
N/A
5.4 MEDIUM
The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
CVE-2022-44721
2022-12-29
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2841. Reason: This issue was MERGED into CVE-2022-2841 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2022-2841 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2022-4472
2023-02-06
N/A
5.4 MEDIUM
The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2022-44718
Netscout, Ngeniusone
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2023-02-07
N/A
3.5 LOW
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.
CVE-2022-44717
Netscout, Ngeniusone
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2023-02-07
N/A
3.1 LOW
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.
CVE-2022-44715
Netscout, Ngeniusone
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2023-02-06
N/A
8.8 HIGH
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.
CVE-2022-44713
2022-12-16
N/A
7.5 HIGH
Microsoft Outlook for Mac Spoofing Vulnerability.
CVE-2022-44710
2022-12-16
N/A
7.8 HIGH
DirectX Graphics Kernel Elevation of Privilege Vulnerability.
CVE-2022-4471
2023-02-23
N/A
5.4 MEDIUM
The YARPP WordPress plugin through 5.30.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
« Previous 1 … 9,052 9,053 9,054 9,055 9,056 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE