Show filters
219 Total Results
Displaying 31-40 of 219
Sort by:
Attacker Value
Unknown
CVE-2023-0750
Disclosure Date: April 06, 2023 (last updated November 08, 2023)
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication.
This would allow an attacker to :
- Change the password, resulting in a DOS of the users
- Change the streaming source, compromising the integrity of the stream
- Change the streaming destination, compromising the confidentiality of the stream
This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.
0
Attacker Value
Unknown
CVE-2020-19695
Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
0
Attacker Value
Unknown
CVE-2020-19692
Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
0
Attacker Value
Unknown
CVE-2023-23063
Disclosure Date: February 22, 2023 (last updated March 08, 2024)
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.
0
Attacker Value
Unknown
CVE-2020-21152
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
0
Attacker Value
Unknown
CVE-2020-35326
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the id value.
0
Attacker Value
Unknown
CVE-2022-45269
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.
0
Attacker Value
Unknown
CVE-2022-3691
Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
0
Attacker Value
Unknown
CVE-2022-45163
Disclosure Date: November 18, 2022 (last updated October 08, 2023)
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)
0
Attacker Value
Unknown
CVE-2022-35173
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.
0