Show filters
809 Total Results
Displaying 261-270 of 809
Sort by:
Attacker Value
Unknown
CVE-2022-22517
Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
0
Attacker Value
Unknown
CVE-2022-22514
Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed, this results in a crash.
0
Attacker Value
Unknown
CVE-2022-22513
Disclosure Date: April 06, 2022 (last updated February 23, 2025)
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
0
Attacker Value
Unknown
CVE-2021-43479
Disclosure Date: March 31, 2022 (last updated October 07, 2023)
A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php.
0
Attacker Value
Unknown
CVE-2022-24661
Disclosure Date: March 08, 2022 (last updated February 23, 2025)
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1). The starview+.exe contains a memory corruption vulnerability while parsing specially crafted .SCE files. This could allow an attacker to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-20665
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user. To exploit this vulnerability, an attacker would need to have valid administrative credentials on an affected device.
0
Attacker Value
Unknown
CVE-2021-45414
Disclosure Date: February 28, 2022 (last updated October 07, 2023)
A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.
0
Attacker Value
Unknown
CVE-2021-25060
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2022-25358
Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.
0
Attacker Value
Unknown
CVE-2021-29398
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application.
0