Show filters
55 Total Results
Displaying 31-40 of 55
Sort by:
Attacker Value
Unknown

CVE-2022-27169

Disclosure Date: May 25, 2022 (last updated February 23, 2025)
An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-40067

Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.
Attacker Value
Unknown

CVE-2021-40066

Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.
Attacker Value
Unknown

CVE-2021-26913

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.
Attacker Value
Unknown

CVE-2021-26915

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
Attacker Value
Unknown

CVE-2021-26912

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
Attacker Value
Unknown

CVE-2020-11585

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.
Attacker Value
Unknown

CVE-2020-5186

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
Attacker Value
Unknown

CVE-2020-5187

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
Attacker Value
Unknown

CVE-2020-5188

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.