Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown

CVE-2021-4443

Disclosure Date: October 16, 2024 (last updated January 06, 2025)
The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code.
0
Attacker Value
Unknown

CVE-2023-2505

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files.
Attacker Value
Unknown

CVE-2023-2504

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
Attacker Value
Unknown

CVE-2022-45163

Disclosure Date: November 18, 2022 (last updated October 08, 2023)
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)
Attacker Value
Unknown

CVE-2022-40629

Disclosure Date: September 21, 2022 (last updated October 08, 2023)
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to insecure design in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to view sensitive information on the targeted device.
Attacker Value
Unknown

CVE-2022-40628

Disclosure Date: September 21, 2022 (last updated October 08, 2023)
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the targeted device.
Attacker Value
Unknown

CVE-2022-40630

Disclosure Date: September 21, 2022 (last updated October 08, 2023)
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to perform session fixation on the targeted device.
Attacker Value
Unknown

CVE-2022-21815

Disclosure Date: February 07, 2022 (last updated October 07, 2023)
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.
Attacker Value
Unknown

CVE-2022-21814

Disclosure Date: February 07, 2022 (last updated October 13, 2023)
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.
Attacker Value
Unknown

CVE-2022-21813

Disclosure Date: February 07, 2022 (last updated October 13, 2023)
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.