Show filters
160 Total Results
Displaying 31-40 of 160
Sort by:
Attacker Value
Unknown
CVE-2022-22828
Disclosure Date: January 27, 2022 (last updated February 23, 2025)
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
0
Attacker Value
Unknown
CVE-2022-23856
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI.
0
Attacker Value
Unknown
CVE-2022-0266
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
0
Attacker Value
Unknown
CVE-2021-44836
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened.
0
Attacker Value
Unknown
CVE-2021-3965
Disclosure Date: January 14, 2022 (last updated February 23, 2025)
Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.
0
Attacker Value
Unknown
CVE-2021-3852
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
growi is vulnerable to Authorization Bypass Through User-Controlled Key
0
Attacker Value
Unknown
CVE-2021-45428
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.
0
Attacker Value
Unknown
CVE-2021-44160
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.
0
Attacker Value
Unknown
CVE-2021-40579
Disclosure Date: December 28, 2021 (last updated February 23, 2025)
https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. The impact is: gain privileges (remote).
0
Attacker Value
Unknown
CVE-2021-24739
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature
0