Show filters
73 Total Results
Displaying 21-30 of 73
Sort by:
Attacker Value
Unknown

CVE-2021-27189

Disclosure Date: February 23, 2021 (last updated February 22, 2025)
The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation.
Attacker Value
Unknown

CVE-2020-8545

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
Global.py in AIL framework 2.8 allows path traversal.
Attacker Value
Unknown

CVE-2018-19830

Disclosure Date: December 31, 2019 (last updated November 08, 2023)
The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's identity.
Attacker Value
Unknown

CVE-2019-5916

Disclosure Date: February 13, 2019 (last updated November 27, 2024)
Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and earlier, Ver 2.7 Government Edition Patch 7 and earlier, Ver 2.8 Patch 6 and earlier, Ver 2.8c Patch 5 and earlier, Ver 2.9 Patch 4 and earlier) allows remote attackers to execute EL expression on the server via unspecified vectors.
Attacker Value
Unknown

CVE-2018-17922

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
0
Attacker Value
Unknown

CVE-2018-17918

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
0
Attacker Value
Unknown

CVE-2018-16672

Disclosure Date: September 26, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information.
Attacker Value
Unknown

CVE-2018-16668

Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
Attacker Value
Unknown

CVE-2018-16670

Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
0
Attacker Value
Unknown

CVE-2018-16671

Disclosure Date: September 18, 2018 (last updated November 27, 2024)
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.
0