Show filters
46 Total Results
Displaying 11-20 of 46
Sort by:
Attacker Value
Unknown

CVE-2024-6078

Disclosure Date: August 14, 2024 (last updated February 26, 2025)
CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud.
0
Attacker Value
Unknown

CVE-2023-37518

Disclosure Date: January 30, 2024 (last updated February 26, 2025)
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
Attacker Value
Unknown

CVE-2023-28527

Disclosure Date: December 09, 2023 (last updated February 25, 2025)
IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206.
Attacker Value
Unknown

CVE-2023-28526

Disclosure Date: December 09, 2023 (last updated February 25, 2025)
IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204.
Attacker Value
Unknown

CVE-2023-28523

Disclosure Date: December 09, 2023 (last updated February 25, 2025)
IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753.
Attacker Value
Unknown

CVE-2023-5136

Disclosure Date: November 08, 2023 (last updated February 25, 2025)
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.
Attacker Value
Unknown

CVE-2023-23997

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions.
Attacker Value
Unknown

CVE-2021-37401

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
Attacker Value
Unknown

CVE-2021-37400

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
Attacker Value
Unknown

CVE-2021-45232

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.