Show filters
142 Total Results
Displaying 11-20 of 142
Sort by:
Attacker Value
Unknown

CVE-2024-5620

Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5619

Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5618

Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2023-51708

Disclosure Date: December 22, 2023 (last updated January 10, 2024)
Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before 23.00.01.25.
Attacker Value
Unknown

CVE-2023-38280

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.
Attacker Value
Unknown

CVE-2023-34838

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter.
Attacker Value
Unknown

CVE-2023-34837

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.
Attacker Value
Unknown

CVE-2023-34836

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.
Attacker Value
Unknown

CVE-2023-34835

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.
Attacker Value
Unknown

CVE-2023-33731

Disclosure Date: June 02, 2023 (last updated October 08, 2023)
Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.