Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2022-32963
Disclosure Date: August 04, 2022 (last updated February 24, 2025)
OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-35216
Disclosure Date: August 04, 2022 (last updated February 24, 2025)
OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-32964
Disclosure Date: August 04, 2022 (last updated February 24, 2025)
OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or disrupt service.
0
Attacker Value
Unknown
CVE-2021-35312
Disclosure Date: August 06, 2021 (last updated February 23, 2025)
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.
0
Attacker Value
Unknown
CVE-2021-31996
Disclosure Date: May 03, 2021 (last updated February 22, 2025)
An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::merge().
0
Attacker Value
Unknown
CVE-2019-16264
Disclosure Date: September 16, 2019 (last updated November 27, 2024)
In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the database.
0
Attacker Value
Unknown
CVE-2006-2988
Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in dictionary.php in Chemical Dictionary allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a browse action.
0