Show filters
1,297 Total Results
Displaying 191-200 of 1,297
Sort by:
Attacker Value
Unknown
CVE-2023-0262
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.
0
Attacker Value
Unknown
CVE-2023-22884
Disclosure Date: January 21, 2023 (last updated February 24, 2025)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.
0
Attacker Value
Unknown
CVE-2015-10026
Disclosure Date: January 07, 2023 (last updated February 24, 2025)
A vulnerability was found in tiredtyrant flairbot. It has been declared as critical. This vulnerability affects unknown code of the file flair.py. The manipulation leads to sql injection. The patch is identified as 5e112b68c6faad1d4699d02c1ebbb7daf48ef8fb. It is recommended to apply a patch to fix this issue. VDB-217618 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-2484
Disclosure Date: January 06, 2023 (last updated February 24, 2025)
The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.
0
Attacker Value
Unknown
CVE-2022-2483
Disclosure Date: January 06, 2023 (last updated February 24, 2025)
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.
0
Attacker Value
Unknown
CVE-2022-2482
Disclosure Date: January 06, 2023 (last updated February 24, 2025)
A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.
0
Attacker Value
Unknown
CVE-2020-11101
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
0
Attacker Value
Unknown
CVE-2022-44565
Disclosure Date: December 23, 2022 (last updated February 24, 2025)
An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.0 and airFiber GBE <1.4.1 that allows a malicious actor to retrieve status and usage data from the UISP device.
0
Attacker Value
Unknown
CVE-2022-46421
Disclosure Date: December 20, 2022 (last updated February 24, 2025)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
0
Attacker Value
Unknown
CVE-2022-37918
Disclosure Date: December 08, 2022 (last updated February 24, 2025)
Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change network configurations with privileges at a higher effective level in Aruba AirWave Management Platform version(s): 8.2.15.0 and below.
0