Show filters
1,297 Total Results
Displaying 241-250 of 1,297
Sort by:
Attacker Value
Unknown
CVE-2022-36266
Disclosure Date: August 08, 2022 (last updated February 24, 2025)
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.
0
Attacker Value
Unknown
CVE-2017-20100
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2022-28620
Disclosure Date: June 24, 2022 (last updated October 07, 2023)
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27; All Slingshot versions prior to 1.7.2; All versions of node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX liquid cooled cabinets prior to 1.6.27/1.5.33/1.4.27. HPE has provided a software update to resolve this vulnerability in HPE Cray Legacy Shasta System Solutions, HPE Slingshot, and HPE Cray EX Supercomputers.
0
Attacker Value
Unknown
CVE-2021-4230
Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. It is recommended to the change the configuration settings.
0
Attacker Value
Unknown
CVE-2022-30367
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
0
Attacker Value
Unknown
CVE-2022-30374
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.
0
Attacker Value
Unknown
CVE-2022-30373
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.
0
Attacker Value
Unknown
CVE-2022-30372
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.
0
Attacker Value
Unknown
CVE-2022-30371
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.
0
Attacker Value
Unknown
CVE-2022-30370
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.
0