Show filters
607 Total Results
Displaying 101-110 of 607
Sort by:
Attacker Value
Unknown

CVE-2022-20861

Disclosure Date: July 20, 2022 (last updated February 24, 2025)
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.
Attacker Value
Unknown

CVE-2022-2141

Disclosure Date: July 19, 2022 (last updated February 24, 2025)
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
Attacker Value
Unknown

CVE-2022-28809

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
Attacker Value
Unknown

CVE-2022-31260

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.
Attacker Value
Unknown

CVE-2021-34538

Disclosure Date: July 16, 2022 (last updated February 24, 2025)
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
Attacker Value
Unknown

CVE-2022-28771

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.
Attacker Value
Unknown

CVE-2022-33138

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). Affected devices do not perform authentication for several web API endpoints. This could allow an unauthenticated remote attacker to read and download data from the device.
Attacker Value
Unknown

CVE-2021-44222

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.
Attacker Value
Unknown

CVE-2022-23719

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack vectors. A successful attack can lead to code executed as SYSTEM by the PingID Windows Login application, or even a denial of service for offline security key authentication.
Attacker Value
Unknown

CVE-2022-31266

Disclosure Date: June 29, 2022 (last updated February 24, 2025)
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.