Show filters
49 Total Results
Displaying 11-20 of 49
Sort by:
Attacker Value
Unknown
CVE-2023-35762
Disclosure Date: November 20, 2023 (last updated November 30, 2023)
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution.
0
Attacker Value
Unknown
CVE-2023-29155
Disclosure Date: November 20, 2023 (last updated November 18, 2024)
Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin-level access to the host system.
0
Attacker Value
Unknown
CVE-2023-4589
Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process lacks digital signatures and fails to validate the integrity of the update package, allowing the attacker to inject malicious applications during the update.
0
Attacker Value
Unknown
CVE-2023-4588
Disclosure Date: September 06, 2023 (last updated October 08, 2023)
File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation of this vulnerability could allow an authenticated user with administrative privileges to create a backup file in the application's webroot directory, changing the default backup directory to the wwwroot folder, and download it with some configuration files such as encryption.config/ and database.config stored in the wwwroot directory, exposing the database credentials in plain text.
0
Attacker Value
Unknown
CVE-2023-30195
Disclosure Date: July 06, 2023 (last updated February 25, 2025)
In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can download personal informations without restriction formatted in json.
0
Attacker Value
Unknown
CVE-2023-2131
Disclosure Date: April 20, 2023 (last updated February 24, 2025)
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-44727
Disclosure Date: November 10, 2022 (last updated February 24, 2025)
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).
0
Attacker Value
Unknown
CVE-2022-31505
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2020-9058
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.
0
Attacker Value
Unknown
CVE-2020-9057
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture and replay Z-Wave traffic. Firmware upgrades cannot directly address this vulnerability as it is an issue with the Z-Wave specification for these legacy chipsets. One way to protect against this vulnerability is to use 500 or 700 series chipsets that support Security 2 (S2) encryption. As examples, the Linear WADWAZ-1 version 3.43 and WAPIRZ-1 version 3.43 (with 300 series chipsets) are vulnerable.
0