Show filters
104 Total Results
Displaying 41-50 of 104
Sort by:
Attacker Value
Unknown
CVE-2021-29425
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
0
Attacker Value
Unknown
CVE-2021-23337
Disclosure Date: February 15, 2021 (last updated February 22, 2025)
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
0
Attacker Value
Unknown
CVE-2020-13527
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-13528
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-20334
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
0
Attacker Value
Unknown
CVE-2018-20335
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
0
Attacker Value
Unknown
CVE-2018-20333
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
0
Attacker Value
Unknown
CVE-2013-3093
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
ASUS RT-N56U devices allow CSRF.
0
Attacker Value
Unknown
CVE-2020-7997
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.
0
Attacker Value
Unknown
CVE-2019-3738
Disclosure Date: September 18, 2019 (last updated November 08, 2023)
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
0