Show filters
467 Total Results
Displaying 111-120 of 467
Sort by:
Attacker Value
Unknown

CVE-2022-44356

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
Attacker Value
Unknown

CVE-2022-40977

Disclosure Date: November 24, 2022 (last updated February 24, 2025)
A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
Attacker Value
Unknown

CVE-2022-38099

Disclosure Date: November 11, 2022 (last updated February 24, 2025)
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-36635

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
Attacker Value
Unknown

CVE-2022-36634

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.
Attacker Value
Unknown

CVE-2022-23144

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.
Attacker Value
Unknown

CVE-2021-45027

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.
Attacker Value
Unknown

CVE-2022-34577

Disclosure Date: July 25, 2022 (last updated October 07, 2023)
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
Attacker Value
Unknown

CVE-2022-34576

Disclosure Date: July 25, 2022 (last updated October 07, 2023)
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
Attacker Value
Unknown

CVE-2022-34570

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.