Show filters
386 Total Results
Displaying 121-130 of 386
Sort by:
Attacker Value
Unknown

CVE-2020-12069

Disclosure Date: December 26, 2022 (last updated February 24, 2025)
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
Attacker Value
Unknown

CVE-2022-37018

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.
Attacker Value
Unknown

CVE-2021-3661

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
Attacker Value
Unknown

CVE-2022-20968

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. A successful exploit could allow the attacker to cause a stack overflow, resulting in possible remote code execution or a denial of service (DoS) condition on an affected device.
Attacker Value
Unknown

CVE-2022-40204

Disclosure Date: December 01, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
Attacker Value
Unknown

CVE-2019-18265

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.
Attacker Value
Unknown

CVE-2022-40304

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
Attacker Value
Unknown

CVE-2022-40303

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
Attacker Value
Unknown

CVE-2022-30694

Disclosure Date: November 08, 2022 (last updated February 24, 2025)
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
Attacker Value
Unknown

CVE-2020-9285

Disclosure Date: October 20, 2022 (last updated October 08, 2023)
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.