Show filters
783 Total Results
Displaying 171-180 of 783
Sort by:
Attacker Value
Unknown

CVE-2022-48289

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Attacker Value
Unknown

CVE-2022-48288

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Attacker Value
Unknown

CVE-2022-43761

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. 
Attacker Value
Unknown

CVE-2022-45190

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.
Attacker Value
Unknown

CVE-2021-37234

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.
Attacker Value
Unknown

CVE-2022-27891

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham instances. It is highly recommended that customers upgrade all affected services to the latest version. This issue affects: Palantir Gotham versions prior to 103.30221005.0.
Attacker Value
Unknown

CVE-2023-25014

Disclosure Date: February 02, 2023 (last updated February 24, 2025)
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
Attacker Value
Unknown

CVE-2023-25013

Disclosure Date: February 02, 2023 (last updated February 24, 2025)
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.
Attacker Value
Unknown

CVE-2021-43447

Disclosure Date: January 23, 2023 (last updated February 24, 2025)
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.
Attacker Value
Unknown

CVE-2023-0052

Disclosure Date: January 20, 2023 (last updated February 24, 2025)
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and modify the device configuration, which could result in the unauthorized user executing unrestricted malicious commands.