Show filters
441 Total Results
Displaying 141-150 of 441
Sort by:
Attacker Value
Unknown

CVE-2021-22500

Disclosure Date: February 06, 2021 (last updated February 22, 2025)
Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.
Attacker Value
Unknown

CVE-2021-22499

Disclosure Date: February 06, 2021 (last updated February 22, 2025)
Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow persistent XSS attack.
Attacker Value
Unknown

CVE-2020-14245

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources.
Attacker Value
Unknown

CVE-2020-14247

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.
Attacker Value
Unknown

CVE-2020-14246

Disclosure Date: February 04, 2021 (last updated February 22, 2025)
HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.
Attacker Value
Unknown

CVE-2020-35272

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields.
Attacker Value
Unknown

CVE-2020-35271

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.
Attacker Value
Unknown

CVE-2021-21470

Disclosure Date: January 12, 2021 (last updated February 22, 2025)
SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-based attacks in applications that accept attacker-controlled XML configuration files. This occurs as logging service does not disable XML external entities when parsing configuration files and a successful exploit would result in limited impact on integrity and availability of the application.
Attacker Value
Unknown

CVE-2018-16243

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
Attacker Value
Unknown

CVE-2020-15481

Disclosure Date: November 13, 2020 (last updated November 28, 2024)
An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling process. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys drivers. This issue is fixed in BurnInTest v9.2, PerformanceTest v10.0 Build 1009, OSForensics v8.0.