Show filters
1,297 Total Results
Displaying 211-220 of 1,297
Sort by:
Attacker Value
Unknown

CVE-2021-34577

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded shared key while being adjacent to the device.
Attacker Value
Unknown

CVE-2022-43982

Disclosure Date: November 02, 2022 (last updated February 24, 2025)
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.
Attacker Value
Unknown

CVE-2022-43985

Disclosure Date: November 02, 2022 (last updated February 24, 2025)
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
Attacker Value
Unknown

CVE-2022-28866

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the permissions for access to resources, it allows a potential attacker to view pages, with sensitive data, that are not allowed, and modify system configurations also causing DoS, which should be accessed only by user with administration profile, bypassing all controls (without checking for user identity).
Attacker Value
Unknown

CVE-2022-41672

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
Attacker Value
Unknown

CVE-2022-40943

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.
Attacker Value
Unknown

CVE-2022-40944

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.
Attacker Value
Unknown

CVE-2022-20728

Disclosure Date: September 27, 2022 (last updated February 24, 2025)
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.
Attacker Value
Unknown

CVE-2022-40298

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.
Attacker Value
Unknown

CVE-2022-40754

Disclosure Date: September 21, 2022 (last updated February 24, 2025)
In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.