Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown
CVE-2020-15787
Disclosure Date: September 09, 2020 (last updated February 22, 2025)
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of characters versus the whole provided string. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.
0
Attacker Value
Unknown
CVE-2020-10257
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
0
Attacker Value
Unknown
CVE-2015-9447
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
0
Attacker Value
Unknown
CVE-2015-9446
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2015-9445
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
0
Attacker Value
Unknown
CVE-2019-12948
Disclosure Date: July 29, 2019 (last updated November 27, 2024)
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-0132
Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially cause a denial of service via network access.
0
Attacker Value
Unknown
CVE-2019-0172
Disclosure Date: May 17, 2019 (last updated November 27, 2024)
A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access.
0
Attacker Value
Unknown
CVE-2019-0101
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access.
0
Attacker Value
Unknown
CVE-2017-5738
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure.
0