Show filters
142 Total Results
Displaying 21-30 of 142
Sort by:
Attacker Value
Unknown

CVE-2023-33732

Disclosure Date: May 31, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.
Attacker Value
Unknown

CVE-2023-33730

Disclosure Date: May 31, 2023 (last updated October 08, 2023)
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.
Attacker Value
Unknown

CVE-2023-31703

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
Attacker Value
Unknown

CVE-2023-31702

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.
Attacker Value
Unknown

CVE-2023-20102

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to insufficient sanitization of user-provided data that is parsed into system memory. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the administrator user.
Attacker Value
Unknown

CVE-2021-29891

Disclosure Date: August 19, 2022 (last updated October 08, 2023)
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
Attacker Value
Unknown

CVE-2017-20121

Disclosure Date: June 30, 2022 (last updated October 07, 2023)
A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Database Management. The manipulation leads to improper privilege management. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-27506

Disclosure Date: April 12, 2022 (last updated October 07, 2023)
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
Attacker Value
Unknown

CVE-2021-38930

Disclosure Date: April 08, 2022 (last updated October 07, 2023)
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.
Attacker Value
Unknown

CVE-2021-38929

Disclosure Date: April 08, 2022 (last updated October 07, 2023)
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.