Show filters
461 Total Results
Displaying 101-110 of 461
Sort by:
Attacker Value
Unknown

CVE-2022-22522

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.
Attacker Value
Unknown

CVE-2022-28813

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device.
Attacker Value
Unknown

CVE-2022-28811

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.
Attacker Value
Unknown

CVE-2022-28816

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.
Attacker Value
Unknown

CVE-2022-22524

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .
Attacker Value
Unknown

CVE-2022-37734

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9.
Attacker Value
Unknown

CVE-2021-37819

Disclosure Date: September 09, 2022 (last updated February 24, 2025)
PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.
Attacker Value
Unknown

CVE-2021-25657

Disclosure Date: September 02, 2022 (last updated February 24, 2025)
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.
Attacker Value
Unknown

CVE-2022-35936

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the internal database storage. However, due to a bug in the `DeleteAccount`function, all contracts that used the identical bytecode (i.e shared the same `CodeHash`) will also stop working once one contract invokes `selfdestruct`, even though the other contracts did not invoke the `selfdestruct` OPCODE. This vulnerability has been patched in Ethermint version v0.18.0. The patch has state machine-breaking changes for applications using Ethermint, so a coordinated upgrade procedure is required. A workaround is available. If a contract is subject to DoS due to this issue, the user can redeploy the same contract, i.e. with identical bytecode, so that the original contract's code is recovered. The new contract deployment restores the `bytecode hash -> bytecode` entry in the internal state.
Attacker Value
Unknown

CVE-2022-2589

Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.