Show filters
219 Total Results
Displaying 31-40 of 219
Sort by:
Attacker Value
Unknown

CVE-2023-0750

Disclosure Date: April 06, 2023 (last updated November 08, 2023)
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising the integrity of the stream - Change the streaming destination, compromising the confidentiality of the stream This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.
Attacker Value
Unknown

CVE-2020-19695

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
Attacker Value
Unknown

CVE-2020-19692

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
Attacker Value
Unknown

CVE-2023-23063

Disclosure Date: February 22, 2023 (last updated March 08, 2024)
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.
Attacker Value
Unknown

CVE-2020-21152

Disclosure Date: January 20, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
Attacker Value
Unknown

CVE-2020-35326

Disclosure Date: January 18, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the id value.
Attacker Value
Unknown

CVE-2022-45269

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.
Attacker Value
Unknown

CVE-2022-3691

Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
Attacker Value
Unknown

CVE-2022-45163

Disclosure Date: November 18, 2022 (last updated October 08, 2023)
An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled configuration, memory contents could potentially leak to physically proximate attackers via the respective SDP port in cold and warm boot attacks. (The recommended mitigation is to completely disable the SDP mode by programming a one-time programmable eFUSE. Customers can contact NXP for additional information.)
Attacker Value
Unknown

CVE-2022-35173

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.