Show filters
16,350 Total Results
Displaying 51-60 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2022-25831

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.
Attacker Value
Unknown

CVE-2021-43442

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by parameter maniulation using PUT and DELETE and by calling the 'UserPermission' endpoint with the ID of created account and set it to 'admin' userType, successfully adding a second administrative account.
Attacker Value
Unknown

CVE-2021-37292

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.
Attacker Value
Unknown

CVE-2022-27128

Disclosure Date: April 10, 2022 (last updated February 23, 2025)
An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.
Attacker Value
Unknown

CVE-2022-25339

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
Attacker Value
Unknown

CVE-2022-25338

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
Attacker Value
Unknown

CVE-2021-46419

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
Attacker Value
Unknown

CVE-2021-46418

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
Attacker Value
Unknown

CVE-2022-23446

Disclosure Date: April 06, 2022 (last updated February 23, 2025)
A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission.
Attacker Value
Unknown

CVE-2022-26635

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.