Show filters
233 topics marked with the following tags:
Displaying 11-20 of 233
Sort by:
Attacker Value
Unknown

CVE-2021-27102

Disclosure Date: February 16, 2021 (last updated October 07, 2023)
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
Attacker Value
Unknown

CVE-2021-38646

Disclosure Date: September 15, 2021 (last updated December 29, 2023)
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2016-3309

Disclosure Date: August 09, 2016 (last updated October 05, 2023)
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.
Attacker Value
Unknown

CVE-2018-2380

Disclosure Date: March 01, 2018 (last updated October 06, 2023)
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Attacker Value
Unknown

CVE-2016-0151

Disclosure Date: April 12, 2016 (last updated October 05, 2023)
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
Attacker Value
Unknown

CVE-2019-16057

Disclosure Date: September 16, 2019 (last updated October 06, 2023)
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
Attacker Value
Unknown

CVE-2022-24682

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
Attacker Value
Very High

CVE-2019-1322

Disclosure Date: October 10, 2019 (last updated October 06, 2023)
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.
Attacker Value
Unknown

CVE-2022-29499

Disclosure Date: April 26, 2022 (last updated October 07, 2023)
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
Attacker Value
Unknown

CVE-2010-1428

Disclosure Date: April 28, 2010 (last updated October 04, 2023)
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
0