Show filters
563 Total Results
Displaying 211-220 of 563
Sort by:
Attacker Value
Unknown

CVE-2022-25570

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.
Attacker Value
Unknown

CVE-2022-25359

Disclosure Date: February 26, 2022 (last updated February 23, 2025)
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
Attacker Value
Unknown

CVE-2022-0673

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.
Attacker Value
Unknown

CVE-2022-0672

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
Attacker Value
Unknown

CVE-2021-43510

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
Attacker Value
Unknown

CVE-2021-43509

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.
Attacker Value
Unknown

CVE-2021-41040

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.
Attacker Value
Unknown

CVE-2021-43779

Disclosure Date: January 05, 2022 (last updated February 23, 2025)
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.
Attacker Value
Unknown

CVE-2021-43837

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest of the contents of the secret as a Jinja2 template. Jinja2 is a powerful templating engine and is not designed to safely render arbitrary templates. An attacker controlling a jinja2 template rendered on a machine can trigger arbitrary code, making this a Remote Code Execution (RCE) risk. If the content of the vault can be completely trusted, then this is not a problem. Otherwise, if your threat model includes cases where an attacker can manipulate a secret value read from the vault using vault-cli, then this vulnerability may impact you. In 3.0.0, the code related to interpreting vault templated secrets has been removed entirely. Users are advised to upgrade as soon as possible. For users unable to upgrade a w…
Attacker Value
Unknown

CVE-2021-41039

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.