Show filters
318 Total Results
Displaying 191-200 of 318
Sort by:
Attacker Value
Unknown

CVE-2021-27760

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
Attacker Value
Unknown

CVE-2021-27777

Disclosure Date: April 10, 2022 (last updated February 23, 2025)
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.
Attacker Value
Unknown

CVE-2021-27764

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
Attacker Value
Unknown

CVE-2022-25017

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.
Attacker Value
Unknown

CVE-2021-27756

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
Attacker Value
Unknown

CVE-2021-27757

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."
Attacker Value
Unknown

CVE-2021-27755

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
"Sametime Android potential path traversal vulnerability when using File class"
Attacker Value
Unknown

CVE-2021-27753

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
"Sametime Android PathTraversal Vulnerability"
Attacker Value
Unknown

CVE-2021-46389

Disclosure Date: February 07, 2022 (last updated February 23, 2025)
IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by an integer overflow in iipsrv.fcgi through malformed HTTP query parameters.
Attacker Value
Unknown

CVE-2022-0121

Disclosure Date: January 06, 2022 (last updated February 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.