Show filters
54 Total Results
Displaying 31-40 of 54
Sort by:
Attacker Value
Unknown
CVE-2018-15511
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2018-15512
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2019-15304
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an attacker to cause a Denial of Service or Information Disclosure via the undocumented access-point configuration page located on the device. This wifi thermometer app requests and requires excessive permissions to operate such as Fine GPS location, camera, applists, Serial number, IMEI. In addition to the "backdoor" login access for "admin" purposes, this accompanying app also establishes connections with several china based URLs to include Alibaba cloud computing. NOTE: this device also ships with ProGrade branding.
0
Attacker Value
Unknown
CVE-2016-10904
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
The olimometer plugin before 2.57 for WordPress has SQL injection.
0
Attacker Value
Unknown
CVE-2019-13099
Disclosure Date: July 22, 2019 (last updated November 27, 2024)
The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.
0
Attacker Value
Unknown
CVE-2019-11826
Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.
0
Attacker Value
Unknown
CVE-2018-13298
Disclosure Date: April 01, 2019 (last updated November 27, 2024)
Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-13628
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for MomentumToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2018-12323
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.
0
Attacker Value
Unknown
CVE-2018-12259
Disclosure Date: June 12, 2018 (last updated November 26, 2024)
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full system compromise.
0