Show filters
55 Total Results
Displaying 31-40 of 55
Sort by:
Attacker Value
Unknown
CVE-2022-27169
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted network request can lead to a disclosure of sensitive information. An attacker can send a network request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-40067
Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.
0
Attacker Value
Unknown
CVE-2021-40066
Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.
0
Attacker Value
Unknown
CVE-2021-26913
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.
0
Attacker Value
Unknown
CVE-2021-26915
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
0
Attacker Value
Unknown
CVE-2021-26912
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
0
Attacker Value
Unknown
CVE-2020-11585
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.
0
Attacker Value
Unknown
CVE-2020-5186
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2020-5187
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
0
Attacker Value
Unknown
CVE-2020-5188
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
0