Show filters
114 Total Results
Displaying 21-30 of 114
Sort by:
Attacker Value
Unknown
CVE-2022-4240
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
0
Attacker Value
Unknown
CVE-2022-46361
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.
0
Attacker Value
Unknown
CVE-2022-43485
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
0
Attacker Value
Unknown
CVE-2022-24632
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.
0
Attacker Value
Unknown
CVE-2022-24631
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.
0
Attacker Value
Unknown
CVE-2022-24630
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.
0
Attacker Value
Unknown
CVE-2022-24629
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.
0
Attacker Value
Unknown
CVE-2022-24628
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php.
0
Attacker Value
Unknown
CVE-2022-24627
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.
0
Attacker Value
Unknown
CVE-2022-41339
Disclosure Date: November 12, 2022 (last updated December 22, 2024)
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
0