Show filters
614 Total Results
Displaying 41-50 of 614
Sort by:
Attacker Value
Unknown
CVE-2024-5514
Disclosure Date: May 30, 2024 (last updated January 05, 2025)
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend system without being recorded in the system logs.
0
Attacker Value
Unknown
CVE-2024-4893
Disclosure Date: May 15, 2024 (last updated January 05, 2025)
DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
0
Attacker Value
Unknown
CVE-2024-4232
Disclosure Date: May 14, 2024 (last updated June 05, 2024)
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system.
Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.
0
Attacker Value
Unknown
CVE-2024-4231
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system.
Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.
0
Attacker Value
Unknown
CVE-2024-2257
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system.
Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.
0
Attacker Value
Unknown
CVE-2024-4466
Disclosure Date: May 03, 2024 (last updated May 04, 2024)
SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to send a specially crafted SQL query to the pass parameter and retrieve all the data stored in the database.
0
Attacker Value
Unknown
CVE-2024-4433
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0.
0
Attacker Value
Unknown
CVE-2024-3072
Disclosure Date: April 30, 2024 (last updated January 05, 2025)
The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary post title, content, and ACF data.
0
Attacker Value
Unknown
CVE-2024-28957
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
0
Attacker Value
Unknown
CVE-2024-28894
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
0