Show filters
723 Total Results
Displaying 151-160 of 723
Sort by:
Attacker Value
Unknown

CVE-2022-43999

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.
Attacker Value
Unknown

CVE-2022-4018

Disclosure Date: November 16, 2022 (last updated February 24, 2025)
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
Attacker Value
Unknown

CVE-2022-42785

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.
Attacker Value
Unknown

CVE-2022-45378

Disclosure Date: November 14, 2022 (last updated February 24, 2025)
In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even lead to arbitrary remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Attacker Value
Unknown

CVE-2021-46852

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Attacker Value
Unknown

CVE-2022-30515

Disclosure Date: November 08, 2022 (last updated February 24, 2025)
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.
Attacker Value
Unknown

CVE-2022-38168

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
Attacker Value
Unknown

CVE-2022-3675

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows booting non-default OSTree deployments without entering a password. This allows someone with access to the GRUB menu to boot into an older version of Fedora CoreOS, reverting any security fixes that have recently been applied to the machine. A password is still required to modify kernel command-line arguments and to access the GRUB command line.
Attacker Value
Unknown

CVE-2022-42473

Disclosure Date: November 02, 2022 (last updated February 24, 2025)
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.
Attacker Value
Unknown

CVE-2022-27582

Disclosure Date: November 01, 2022 (last updated February 24, 2025)
Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The firmware versions <=1.10.1 allow to optionally disable device configuration over the network interfaces. Please make sure that you apply general security practices when operating the SIM4000. A fix is planned but not yet scheduled.