Show filters
203 Total Results
Displaying 121-130 of 203
Sort by:
Attacker Value
Unknown

CVE-2021-3958

Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Injection.This issue affects Ipack SCADA Software: from unspecified before 1.1.0.
0
Attacker Value
Unknown

CVE-2021-44518

Disclosure Date: December 02, 2021 (last updated February 23, 2025)
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (lock or unlock) activated via the companion app. The code is sent unencrypted, allowing any attacker with the same app (either Android or iOS) to add the lock and take complete control. For successful exploitation, the attacker must be able to touch the lock's power button, and must be able to capture BLE network communication.
Attacker Value
Unknown

CVE-2021-24390

Disclosure Date: September 06, 2021 (last updated February 23, 2025)
A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through 3.7.2 is not sanitised, properly escaped or validated before inserting to a SQL statement not delimited by quotes, leading to SQL injection.
Attacker Value
Unknown

CVE-2021-35438

Disclosure Date: June 23, 2021 (last updated February 22, 2025)
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
Attacker Value
Unknown

CVE-2021-23328

Disclosure Date: January 29, 2021 (last updated February 22, 2025)
This affects all versions of package iniparserjs. This vulnerability relates when ini_parser.js is concentrating arrays. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
0
Attacker Value
Unknown

CVE-2020-13225

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.
Attacker Value
Unknown

CVE-2020-1722

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-7988

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.
Attacker Value
Unknown

CVE-2019-6019

Disclosure Date: December 26, 2019 (last updated November 27, 2024)
Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Attacker Value
Unknown

CVE-2019-14867

Disclosure Date: November 27, 2019 (last updated November 08, 2023)
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.