Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown

CVE-2022-31505

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2020-4409

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 179537.
Attacker Value
Unknown

CVE-2019-4446

Disclosure Date: April 16, 2020 (last updated November 27, 2024)
IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifying request parameters. IBM X-Force ID: 163490.
Attacker Value
Unknown

CVE-2019-4644

Disclosure Date: April 16, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.
Attacker Value
Unknown

CVE-2019-4749

Disclosure Date: April 16, 2020 (last updated February 21, 2025)
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.
Attacker Value
Unknown

CVE-2019-16880

Disclosure Date: September 25, 2019 (last updated November 27, 2024)
An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method.
Attacker Value
Unknown

CVE-2019-1010221

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` can also be set in a normal adb shell session. The component is: adb shell (patches to fix this are at https://review.lineageos.org/c/LineageOS/android_system_core/+/234800, https://review.lineageos.org/c/LineageOS/android_device_lineage_sepolicy/+/234799). The attack vector is: When adb is enabled, and an attacker has physical access, `adb shell setprop service.adb.root 1` allows restarting adb as root.
0
Attacker Value
Unknown

CVE-2019-7257

Disclosure Date: July 02, 2019 (last updated November 27, 2024)
Linear eMerge E3-Series devices allow Unrestricted File Upload.
Attacker Value
Unknown

CVE-2019-7255

Disclosure Date: July 02, 2019 (last updated November 27, 2024)
Linear eMerge E3-Series devices allow XSS.
Attacker Value
Unknown

CVE-2019-7253

Disclosure Date: July 02, 2019 (last updated November 27, 2024)
Linear eMerge E3-Series devices allow Directory Traversal.
0