Show filters
191 Total Results
Displaying 121-130 of 191
Sort by:
Attacker Value
Unknown
CVE-2021-35962
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.
0
Attacker Value
Unknown
CVE-2021-29510
Disclosure Date: May 13, 2021 (last updated February 22, 2025)
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic. If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to u…
0
Attacker Value
Unknown
CVE-2020-27268
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass checks for default PINs via Bluetooth Low Energy.
0
Attacker Value
Unknown
CVE-2020-27256
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin therapy settings.
0
Attacker Value
Unknown
CVE-2020-27272
Disclosure Date: January 19, 2021 (last updated November 28, 2024)
SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.
0
Attacker Value
Unknown
CVE-2020-27270
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).
0
Attacker Value
Unknown
CVE-2020-35604
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
0
Attacker Value
Unknown
CVE-2020-7737
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
0
Attacker Value
Unknown
CVE-2020-14982
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data from the database.
0
Attacker Value
Unknown
CVE-2020-3934
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command.
0