Show filters
178 Total Results
Displaying 21-30 of 178
Sort by:
Attacker Value
Unknown
CVE-2022-1073
Disclosure Date: March 29, 2022 (last updated October 07, 2023)
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.
0
Attacker Value
Unknown
CVE-2022-0654
Disclosure Date: February 23, 2022 (last updated October 07, 2023)
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.
0
Attacker Value
Unknown
CVE-2021-44031
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}.
0
Attacker Value
Unknown
CVE-2021-44030
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
0
Attacker Value
Unknown
CVE-2021-44029
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
0
Attacker Value
Unknown
CVE-2021-44028
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.
0
Attacker Value
Unknown
CVE-2021-31597
Disclosure Date: April 23, 2021 (last updated February 22, 2025)
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
0
Attacker Value
Unknown
CVE-2020-35308
Disclosure Date: March 31, 2021 (last updated November 28, 2024)
CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code.
0
Attacker Value
Unknown
CVE-2020-28502
Disclosure Date: March 05, 2021 (last updated February 22, 2025)
This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.
0
Attacker Value
Unknown
CVE-2020-35724
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indirectly via the cpr, tcp, or abs parameter). NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0