Show filters
108 Total Results
Displaying 31-40 of 108
Sort by:
Attacker Value
Unknown

CVE-2021-33020

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Attacker Value
Unknown

CVE-2021-33018

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information.
Attacker Value
Unknown

CVE-2021-27501

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.
Attacker Value
Unknown

CVE-2021-27497

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Attacker Value
Unknown

CVE-2021-27493

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
Attacker Value
Unknown

CVE-2022-21660

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the `setUserInfo` function. Users are advised to update as soon as possible. There are no known workarounds.
Attacker Value
Unknown

CVE-2021-45105

Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Attacker Value
Unknown

CVE-2021-44219

Disclosure Date: November 24, 2021 (last updated October 07, 2023)
Gin-Vue-Admin before 2.4.6 mishandles a SQL database.
Attacker Value
Unknown

CVE-2021-3794

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
vuelidate is vulnerable to Inefficient Regular Expression Complexity
Attacker Value
Unknown

CVE-2021-34429

Disclosure Date: July 15, 2021 (last updated February 23, 2025)
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.