Show filters
76 Total Results
Displaying 31-40 of 76
Sort by:
Attacker Value
Unknown

CVE-2021-32033

Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in certain situations. The time value used by the device can be set independently from the used seed value for generating time-based one-time passwords, without authentication. Thus, an attacker with short-time physical access to a device can set the internal real-time clock (RTC) to the future, generate one-time passwords, and reset the clock to the current time. This allows the generation of valid future time-based one-time passwords without having further access to the hardware token.
Attacker Value
Unknown

CVE-2020-29577

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
Attacker Value
Unknown

CVE-2020-24246

Disclosure Date: October 07, 2020 (last updated November 28, 2024)
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
Attacker Value
Unknown

CVE-2013-4412

Disclosure Date: November 04, 2019 (last updated December 14, 2023)
slim has NULL pointer dereference when using crypt() method from glibc 2.17
Attacker Value
Unknown

CVE-2019-15112

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
Attacker Value
Unknown

CVE-2015-9273

Disclosure Date: October 07, 2018 (last updated November 27, 2024)
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking.
0
Attacker Value
Unknown

CVE-2018-12658

Disclosure Date: June 22, 2018 (last updated November 26, 2024)
Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI.
Attacker Value
Unknown

CVE-2018-12656

Disclosure Date: June 22, 2018 (last updated November 26, 2024)
Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI.
0
Attacker Value
Unknown

CVE-2018-12657

Disclosure Date: June 22, 2018 (last updated November 26, 2024)
Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.
0
Attacker Value
Unknown

CVE-2018-12655

Disclosure Date: June 22, 2018 (last updated November 26, 2024)
Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.
0