Show filters
73 Total Results
Displaying 1-10 of 73
Sort by:
Attacker Value
Unknown
CVE-2024-51589
Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpcirqle Bigmart Elements allows DOM-Based XSS.This issue affects Bigmart Elements: from n/a through 1.0.3.
0
Attacker Value
Unknown
CVE-2024-8891
Disclosure Date: September 18, 2024 (last updated September 27, 2024)
An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.
0
Attacker Value
Unknown
CVE-2024-8892
Disclosure Date: September 18, 2024 (last updated October 08, 2024)
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.
0
Attacker Value
Unknown
CVE-2024-8890
Disclosure Date: September 18, 2024 (last updated October 02, 2024)
An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could obtain legitimate credentials or steal sessions due to the fact that the device only implements the HTTP protocol. This fact prevents a secure communication channel from being established.
0
Attacker Value
Unknown
CVE-2024-8889
Disclosure Date: September 18, 2024 (last updated October 08, 2024)
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.
0
Attacker Value
Unknown
CVE-2024-8888
Disclosure Date: September 18, 2024 (last updated October 02, 2024)
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods such as network captures, locally stored web information, etc.
0
Attacker Value
Unknown
CVE-2024-8887
Disclosure Date: September 18, 2024 (last updated October 02, 2024)
CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the device.
0
Attacker Value
Unknown
CVE-2024-0643
Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.
0
Attacker Value
Unknown
CVE-2024-0642
Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.
0
Attacker Value
Unknown
CVE-2023-34181
Disclosure Date: November 09, 2023 (last updated November 15, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WP-Cirrus plugin <= 0.6.11 versions.
0