Show filters
662 Total Results
Displaying 281-290 of 662
Sort by:
Attacker Value
Unknown

CVE-2022-29093

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.
Attacker Value
Unknown

CVE-2022-29092

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.
Attacker Value
Unknown

CVE-2022-29095

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system.
Attacker Value
Unknown

CVE-2022-29094

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system.
Attacker Value
Unknown

CVE-2022-1840

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This issue affects register.php?link=registerand. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but demands authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2022-1839

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affects the file login.php. The manipulation of the argument email with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(2)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. The attack can be initiated remotely but it requires authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2022-1838

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2022-1837

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2022-27094

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
Attacker Value
Unknown

CVE-2022-30052

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.