Show filters
796 Total Results
Displaying 211-220 of 796
Sort by:
Attacker Value
Unknown

CVE-2022-25882

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
Attacker Value
Unknown

CVE-2022-3430

Disclosure Date: January 23, 2023 (last updated February 24, 2025)
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Attacker Value
Unknown

CVE-2020-21152

Disclosure Date: January 20, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
Attacker Value
Unknown

CVE-2023-23596

Disclosure Date: January 20, 2023 (last updated February 24, 2025)
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.
Attacker Value
Unknown

CVE-2020-35326

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the id value.
Attacker Value
Unknown

CVE-2022-45269

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.
Attacker Value
Unknown

CVE-2022-39909

Disclosure Date: December 08, 2022 (last updated February 24, 2025)
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.
Attacker Value
Unknown

CVE-2022-41743

Disclosure Date: October 19, 2022 (last updated February 24, 2025)
NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file. The issue affects only NGINX Plus when the hls directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_hls_module.
Attacker Value
Unknown

CVE-2022-41741

Disclosure Date: October 19, 2022 (last updated February 24, 2025)
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
Attacker Value
Unknown

CVE-2022-36508

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetAPInfoById.