Show filters
783 Total Results
Displaying 171-180 of 783
Sort by:
Attacker Value
Unknown
CVE-2022-48289
Disclosure Date: February 09, 2023 (last updated February 24, 2025)
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
0
Attacker Value
Unknown
CVE-2022-48288
Disclosure Date: February 09, 2023 (last updated February 24, 2025)
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
0
Attacker Value
Unknown
CVE-2022-43761
Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Missing authentication when creating and
managing the B&R APROL database in versions < R 4.2-07
allows reading and changing the system configuration.
0
Attacker Value
Unknown
CVE-2022-45190
Disclosure Date: February 08, 2023 (last updated February 24, 2025)
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.
0
Attacker Value
Unknown
CVE-2021-37234
Disclosure Date: February 03, 2023 (last updated February 24, 2025)
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.
0
Attacker Value
Unknown
CVE-2022-27891
Disclosure Date: February 03, 2023 (last updated February 24, 2025)
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham instances. It is highly recommended that customers upgrade all affected services to the latest version. This issue affects: Palantir Gotham versions prior to 103.30221005.0.
0
Attacker Value
Unknown
CVE-2023-25014
Disclosure Date: February 02, 2023 (last updated February 24, 2025)
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
0
Attacker Value
Unknown
CVE-2023-25013
Disclosure Date: February 02, 2023 (last updated February 24, 2025)
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users.
0
Attacker Value
Unknown
CVE-2021-43447
Disclosure Date: January 23, 2023 (last updated February 24, 2025)
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.
0
Attacker Value
Unknown
CVE-2023-0052
Disclosure Date: January 20, 2023 (last updated February 24, 2025)
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and modify the device configuration, which could result in the unauthorized user executing unrestricted malicious commands.
0