Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2024-12860

Disclosure Date: February 18, 2025 (last updated February 23, 2025)
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Attacker Value
Unknown

CVE-2023-5844

Disclosure Date: October 30, 2023 (last updated February 25, 2025)
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
Attacker Value
Unknown

CVE-2023-4381

Disclosure Date: August 16, 2023 (last updated February 25, 2025)
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
Attacker Value
Unknown

CVE-2023-3069

Disclosure Date: June 02, 2023 (last updated February 25, 2025)
Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
Attacker Value
Unknown

CVE-2023-25931

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy application, which has greater control over therapy parameters than the patient app. Changes still cannot be made outside of the established therapy parameters of the programmer. For unauthorized access to occur, an individual would need physical access to the Smart Programmer.
Attacker Value
Unknown

CVE-2022-3152

Disclosure Date: September 07, 2022 (last updated February 24, 2025)
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
Attacker Value
Unknown

CVE-2022-2930

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
Attacker Value
Unknown

CVE-2022-21935

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
Attacker Value
Unknown

CVE-2022-21934

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.
Attacker Value
Unknown

CVE-2021-34785

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.