Show filters
560 Total Results
Displaying 121-130 of 560
Sort by:
Attacker Value
Unknown

CVE-2021-38289

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts.
Attacker Value
Unknown

CVE-2022-34765

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
Attacker Value
Unknown

CVE-2022-30929

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
Attacker Value
Unknown

CVE-2022-2227

Disclosure Date: July 01, 2022 (last updated February 24, 2025)
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions
Attacker Value
Unknown

CVE-2014-0068

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
Attacker Value
Unknown

CVE-2022-23725

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
Attacker Value
Unknown

CVE-2022-34043

Disclosure Date: June 29, 2022 (last updated February 24, 2025)
Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack and execute arbitrary code.
Attacker Value
Unknown

CVE-2022-34012

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
Attacker Value
Unknown

CVE-2021-20355

Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 194891.
Attacker Value
Unknown

CVE-2021-38879

Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 209057.