Show filters
525 Total Results
Displaying 91-100 of 525
Sort by:
Attacker Value
Unknown
CVE-2022-23725
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
0
Attacker Value
Unknown
CVE-2022-34043
Disclosure Date: June 29, 2022 (last updated February 24, 2025)
Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-34012
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
0
Attacker Value
Unknown
CVE-2021-20355
Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 194891.
0
Attacker Value
Unknown
CVE-2021-38879
Disclosure Date: June 22, 2022 (last updated February 24, 2025)
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 209057.
0
Attacker Value
Unknown
CVE-2022-1596
Disclosure Date: June 21, 2022 (last updated February 23, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
0
Attacker Value
Unknown
CVE-2022-31464
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.
0
Attacker Value
Unknown
CVE-2022-32155
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now binds the management port to localhost preventing remote logins by default. If management services are not required in versions before 9.0, set disableDefaultPort = true in server.conf OR allowRemoteLogin = never in server.conf OR mgmtHostPort = localhost in web.conf. See Configure universal forwarder management security (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security) for more information on disabling the remote management services.
0
Attacker Value
Unknown
CVE-2022-31465
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2.11 Update 11), Xpedition Designer VX.2.12 (All versions < VX.2.12 Update 5), Xpedition Designer VX.2.13 (All versions < VX.2.13 Update 1). The affected application assigns improper access rights to the service executable. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
0
Attacker Value
Unknown
CVE-2021-40649
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
0