Show filters
317 Total Results
Displaying 1-10 of 317
Sort by:
Attacker Value
Unknown
CVE-2022-47617
Disclosure Date: May 02, 2023 (last updated February 25, 2025)
Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt system files using the hard-coded keys for file access, modification, and cause service disruption.
1
Attacker Value
Unknown
CVE-2023-30602
Disclosure Date: May 02, 2023 (last updated February 25, 2025)
Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.
1
Attacker Value
Unknown
CVE-2022-26389
Disclosure Date: February 07, 2025 (last updated February 08, 2025)
An improper access control vulnerability may allow privilege escalation.This issue affects:
* ELI 380 Resting Electrocardiograph:
Versions 2.6.0 and prior;
* ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph:
Versions 2.3.1 and prior;
* ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 and prior;
* ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph:
Versions 2.2.0 and prior.
0
Attacker Value
Unknown
CVE-2025-23527
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Missing Authorization vulnerability in Hemnath Mouli WC Wallet allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WC Wallet: from n/a through 2.2.0.
0
Attacker Value
Unknown
CVE-2025-0683
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text
patient data to a hard-coded public IP address when a patient is hooked
up to the monitor. This could lead to a leakage of confidential patient
data to any device with that IP address or an attacker in a
machine-in-the-middle scenario.
0
Attacker Value
Unknown
CVE-2025-0626
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Contec Health CMS8000 Patient Monitor sends out remote access requests to a hard-coded IP address, bypassing existing device network settings to do so. This could serve as a backdoor and lead to a malicious actor being able to upload and overwrite files on the device.
0
Attacker Value
Unknown
CVE-2024-12248
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
0
Attacker Value
Unknown
CVE-2025-24663
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Ruhul Amin, Josh Lobe Simple Download Monitor allows Blind SQL Injection. This issue affects Simple Download Monitor: from n/a through 3.9.25.
0
Attacker Value
Unknown
CVE-2025-23609
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Helmuth Lammer Tagesteller allows Reflected XSS. This issue affects Tagesteller: from n/a through v.1.1.
0
Attacker Value
Unknown
CVE-2025-23922
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder allows Upload a Web Shell to a Web Server.This issue affects iSpring Embedder: from n/a through 1.0.
0