Show filters
1,297 Total Results
Displaying 241-250 of 1,297
Sort by:
Attacker Value
Unknown

CVE-2022-36266

Disclosure Date: August 08, 2022 (last updated February 24, 2025)
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.
Attacker Value
Unknown

CVE-2017-20100

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-28620

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27; All Slingshot versions prior to 1.7.2; All versions of node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27. HPE has provided a software update to resolve this vulnerability in HPE Cray Legacy Shasta System Solutions, HPE Slingshot, and HPE Cray EX Supercomputers.
Attacker Value
Unknown

CVE-2021-4230

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. It is recommended to the change the configuration settings.
Attacker Value
Unknown

CVE-2022-30367

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
Attacker Value
Unknown

CVE-2022-30374

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.
Attacker Value
Unknown

CVE-2022-30373

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.
Attacker Value
Unknown

CVE-2022-30372

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.
Attacker Value
Unknown

CVE-2022-30371

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.
Attacker Value
Unknown

CVE-2022-30370

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.