Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2021-35243
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.
0
Attacker Value
Unknown
CVE-2021-42128
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.
0
Attacker Value
Unknown
CVE-2021-26614
Disclosure Date: November 22, 2021 (last updated February 23, 2025)
ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.
0
Attacker Value
Unknown
CVE-2021-28809
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later
0
Attacker Value
Unknown
CVE-2020-2503
Disclosure Date: December 23, 2020 (last updated February 22, 2025)
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
0
Attacker Value
Unknown
CVE-2019-20923
Disclosure Date: November 30, 2020 (last updated February 22, 2025)
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript exceptions containing types intended to be scoped to the Javascript engine's internals. This issue affects MongoDB Server v4.0 versions prior to 4.0.7.
0
Attacker Value
Unknown
CVE-2020-12927
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system.
0
Attacker Value
Unknown
CVE-2020-12912
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access.
0
Attacker Value
Unknown
CVE-2020-27123
Disclosure Date: November 04, 2020 (last updated February 22, 2025)
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process on an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device.
0
Attacker Value
Unknown
CVE-2020-12928
Disclosure Date: October 13, 2020 (last updated February 22, 2025)
A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system.
0