Show filters
250 Total Results
Displaying 21-30 of 250
Sort by:
Attacker Value
Unknown
CVE-2023-39223
Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Stored cross-site scripting vulnerability exists in CGIs included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
0
Attacker Value
Unknown
CVE-2024-1618
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. An attacker with local user privileges could exploit this vulnerability to replace the legitimate DFServ.exe service executable with a malicious file of the same name and located in a directory that has a higher priority than the legitimate directory. Thus, when the service starts, it will run the malicious file instead of the legitimate executable, allowing the attacker to execute arbitrary code, gain unauthorized access to the compromised system or stop the service from running.
0
Attacker Value
Unknown
CVE-2024-2049
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
0
Attacker Value
Unknown
CVE-2023-47267
Disclosure Date: December 19, 2023 (last updated December 29, 2023)
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.
0
Attacker Value
Unknown
CVE-2023-31048
Disclosure Date: December 12, 2023 (last updated December 19, 2023)
The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.
0
Attacker Value
Unknown
CVE-2023-3379
Disclosure Date: November 20, 2023 (last updated October 02, 2024)
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
0
Attacker Value
Unknown
CVE-2023-4089
Disclosure Date: October 17, 2023 (last updated October 25, 2023)
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
0
Attacker Value
Unknown
CVE-2022-36228
Disclosure Date: October 09, 2023 (last updated October 13, 2023)
Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device password in the Nokelock app.
0
Attacker Value
Unknown
CVE-2023-1698
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
0
Attacker Value
Unknown
CVE-2022-4899
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
0