Show filters
81 Total Results
Displaying 11-20 of 81
Sort by:
Attacker Value
Unknown

CVE-2023-45685

Disclosure Date: October 16, 2023 (last updated October 25, 2023)
Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal
Attacker Value
Unknown

CVE-2023-30961

Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.
Attacker Value
Unknown

CVE-2022-44215

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
Attacker Value
Unknown

CVE-2023-2290

Disclosure Date: June 26, 2023 (last updated September 16, 2024)
A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-27745

Disclosure Date: June 02, 2023 (last updated October 08, 2023)
An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server.
Attacker Value
Unknown

CVE-2023-27744

Disclosure Date: June 02, 2023 (last updated October 08, 2023)
An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalation leading to remote code execution.
Attacker Value
Unknown

CVE-2023-22629

Disclosure Date: February 14, 2023 (last updated October 08, 2023)
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any file and then move it anywhere on the server's filesystem.
Attacker Value
Unknown

CVE-2022-40134

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-40055

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.
Attacker Value
Unknown

CVE-2022-2877

Disclosure Date: September 16, 2022 (last updated October 08, 2023)
The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.