Show filters
74 Total Results
Displaying 21-30 of 74
Sort by:
Attacker Value
Unknown
CVE-2023-28110
Disclosure Date: March 16, 2023 (last updated October 08, 2023)
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes cluster through Koko can result in the execution of dangerous commands that may disrupt the Koko container environment and affect normal usage. The vulnerability has been fixed in v2.28.8.
0
Attacker Value
Unknown
CVE-2022-1038
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.
0
Attacker Value
Unknown
CVE-2022-36565
Disclosure Date: August 30, 2022 (last updated October 08, 2023)
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
0
Attacker Value
Unknown
CVE-2021-22817
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
0
Attacker Value
Unknown
CVE-2021-3169
Disclosure Date: July 23, 2021 (last updated February 23, 2025)
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
0
Attacker Value
Unknown
CVE-2019-18362
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
0
Attacker Value
Unknown
CVE-2019-11517
Disclosure Date: June 10, 2019 (last updated November 27, 2024)
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.
0
Attacker Value
Unknown
CVE-2019-3817
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.
0
Attacker Value
Unknown
CVE-2018-1000848
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be exploitable via payload onmouseover. This vulnerability appears to have been fixed in 3.1.5 and later.
0
Attacker Value
Unknown
CVE-2018-1000666
Disclosure Date: September 06, 2018 (last updated November 08, 2023)
GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in method: notifySpaceModification; that can result in Improper validation of parameters results in command execution. This attack appear to be exploitable via Network connectivity, required minimal auth privileges (everyone can register an account). This vulnerability appears to have been fixed in After commit 15443122ed2b1cbfd7bdefc048bf106f075becdb.
0