Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 10

Found 229 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2022-41931 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in xwiki-platform-icon-ui xwikixwiki-platform Critical 9.9 2022-11-23 00:00:00 Deep Dive
CVE-2022-41932 Creation of new database tables through login form on PostgreSQL xwikixwiki-platform High 7.5 2022-11-23 00:00:00 Deep Dive
CVE-2022-41933 Plaintext storage of password in org.xwiki.platform:xwiki-platform-security-authentication-default xwikixwiki-platform Medium 6.2 2022-11-23 00:00:00 Deep Dive
CVE-2022-41934 Improper Neutralization of Directives in Dynamically Evaluated Code in org.xwiki.platform:xwiki-platform-menu-ui xwikixwiki-platform Critical 9.9 2022-11-23 00:00:00 Deep Dive
CVE-2022-41935 Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-ui xwikixwiki-platform Medium 5.3 2022-11-23 00:00:00 Deep Dive
CVE-2022-41936 Exposure of Private Personal Information to an Unauthorized Actor in xwiki-platform-rest-server xwikixwiki-platform Medium 5.3 2022-11-22 00:00:00 Deep Dive
CVE-2022-41937 Missing Authorization in XWiki Platform xwikixwiki-platform Critical 9.6 2022-11-22 00:00:00 Deep Dive
CVE-2022-36100 XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection xwikixwiki-platform Critical 9.9 2022-09-08 21:10:10 Deep Dive
CVE-2022-36098 XWiki Platform Mentions UI vulnerable to Cross-site Scripting xwikixwiki-platform High 8.9 2022-09-08 20:50:11 Deep Dive
CVE-2022-36099 XWiki Platform Wiki UI Main Wiki Eval Injection vulnerability xwikixwiki-platform Critical 9.9 2022-09-08 20:45:14 Deep Dive
CVE-2022-36097 XWiki Platform Attachment UI vulnerable to cross-site scripting in the move attachment form xwikixwiki-platform High 8.9 2022-09-08 20:35:11 Deep Dive
CVE-2022-36096 XWiki Platform vulnerable to Cross-site Scripting in the deleted attachments list xwikixwiki-platform High 8.9 2022-09-08 20:30:13 Deep Dive
CVE-2022-36095 XWiki Cross-Site Request Forgery (CSRF) for actions on tags xwikixwiki-platform Medium 4.3 2022-09-08 20:20:13 Deep Dive
CVE-2022-36094 XWiki Platform Web Parent POM vulnerable to XSS in the attachment history xwikixwiki-platform High 8.9 2022-09-08 20:10:09 Deep Dive
CVE-2022-36093 XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution Wizard xwikixwiki-platform High 8.5 2022-09-08 17:25:10 Deep Dive
CVE-2022-36092 XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Action xwikixwiki-platform High 7.5 2022-09-08 17:15:15 Deep Dive
CVE-2022-36091 XWiki Platform Web Templates vulnerable to Missing Authorization and Exposure of Private Personal Information to an Unauthorized Actor xwikixwiki-platform High 7.5 2022-09-08 16:10:09 Deep Dive
CVE-2022-36090 org.xwiki.platform:xwiki-platform-oldcore Improper Authorization check for inactive users xwikixwiki-platform High 8.1 2022-09-08 14:45:13 Deep Dive
CVE-2022-31166 XWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groups xwikixwiki-platform High 8.1 2022-09-07 14:10:12 Deep Dive
CVE-2022-31167 XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference xwikixwiki-platform High 7.1 2022-09-07 13:55:11 Deep Dive