Show filters
563 Total Results
Displaying 211-220 of 563
Sort by:
Attacker Value
Unknown
CVE-2022-25570
Disclosure Date: March 21, 2022 (last updated February 23, 2025)
In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all other password lists in the same folder.
0
Attacker Value
Unknown
CVE-2022-25359
Disclosure Date: February 26, 2022 (last updated February 23, 2025)
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
0
Attacker Value
Unknown
CVE-2022-0673
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.
0
Attacker Value
Unknown
CVE-2022-0672
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
0
Attacker Value
Unknown
CVE-2021-43510
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
0
Attacker Value
Unknown
CVE-2021-43509
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.
0
Attacker Value
Unknown
CVE-2021-41040
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.
0
Attacker Value
Unknown
CVE-2021-43779
Disclosure Date: January 05, 2022 (last updated February 23, 2025)
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.
0
Attacker Value
Unknown
CVE-2021-43837
Disclosure Date: December 16, 2021 (last updated February 23, 2025)
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest of the contents of the secret as a Jinja2 template. Jinja2 is a powerful templating engine and is not designed to safely render arbitrary templates. An attacker controlling a jinja2 template rendered on a machine can trigger arbitrary code, making this a Remote Code Execution (RCE) risk. If the content of the vault can be completely trusted, then this is not a problem. Otherwise, if your threat model includes cases where an attacker can manipulate a secret value read from the vault using vault-cli, then this vulnerability may impact you. In 3.0.0, the code related to interpreting vault templated secrets has been removed entirely. Users are advised to upgrade as soon as possible. For users unable to upgrade a w…
0
Attacker Value
Unknown
CVE-2021-41039
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.
0