Show filters
247 Total Results
Displaying 41-50 of 247
Sort by:
Attacker Value
Unknown
CVE-2023-24104
Disclosure Date: February 23, 2023 (last updated October 08, 2023)
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
0
Attacker Value
Unknown
CVE-2023-23382
Disclosure Date: February 14, 2023 (last updated October 08, 2023)
Azure Machine Learning Compute Instance Information Disclosure Vulnerability
0
Attacker Value
Unknown
CVE-2022-48074
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
An issue in NoMachine before v8.2.3 allows attackers to execute arbitrary commands via a crafted .nxs file.
0
Attacker Value
Unknown
CVE-2022-2988
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to V2.1.0), EcoStruxure Machine Expert – HVAC (Versions prior to V1.4.0)
0
Attacker Value
Unknown
CVE-2015-10069
Disclosure Date: January 19, 2023 (last updated October 08, 2023)
A vulnerability was found in viakondratiuk cash-machine. It has been declared as critical. This vulnerability affects the function is_card_pin_at_session/update_failed_attempts of the file machine.py. The manipulation leads to sql injection. The name of the patch is 62a6e24efdfa195b70d7df140d8287fdc38eb66d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218896.
0
Attacker Value
Unknown
CVE-2022-39429
Disclosure Date: January 18, 2023 (last updated October 08, 2023)
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
0
Attacker Value
Unknown
CVE-2022-39419
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java VM accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
0
Attacker Value
Unknown
CVE-2022-34043
Disclosure Date: June 29, 2022 (last updated October 07, 2023)
Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2021-33436
Disclosure Date: April 28, 2022 (last updated October 07, 2023)
NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM.
0
Attacker Value
Unknown
CVE-2022-26982
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose any PHP code that they wish to have executed on the server.
0