Show filters
529 Total Results
Displaying 301-310 of 529
Sort by:
Attacker Value
Unknown
CVE-2018-10910
Disclosure Date: January 28, 2019 (last updated November 27, 2024)
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
0
Attacker Value
Unknown
CVE-2018-20382
Disclosure Date: December 23, 2018 (last updated November 27, 2024)
Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
0
Attacker Value
Unknown
CVE-2018-17137
Disclosure Date: September 17, 2018 (last updated November 27, 2024)
Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2018-16704
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possible for attackers (logged in users) to view profile page of other users, as demonstrated by navigating to user/3 on demo.gleezcms.org.
0
Attacker Value
Unknown
CVE-2018-16703
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side access control and login attempt limit enforcement. An attacker could exploit this vulnerability by sending modified login attempts to the Portal login page. An exploit could allow the attacker to identify existing users and perform brute-force password attacks on the Portal, as demonstrated by navigating to the user/4 URI.
0
Attacker Value
Unknown
CVE-2018-16347
Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered in Gleez CMS v1.2.0. There is XSS via media/imagecache/resize.
0
Attacker Value
Unknown
CVE-2018-15845
Disclosure Date: August 25, 2018 (last updated November 27, 2024)
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
0
Attacker Value
Unknown
CVE-2018-1999021
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile page.
0
Attacker Value
Unknown
CVE-2018-13340
Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
0
Attacker Value
Unknown
CVE-2018-12924
Disclosure Date: June 28, 2018 (last updated November 26, 2024)
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.
0