Show filters
100 Total Results
Displaying 41-50 of 100
Sort by:
Attacker Value
Unknown
CVE-2020-10791
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
0
Attacker Value
Unknown
CVE-2020-10789
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
0
Attacker Value
Unknown
CVE-2020-10790
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
0
Attacker Value
Unknown
CVE-2020-10792
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
0
Attacker Value
Unknown
CVE-2015-2909
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."
0
Attacker Value
Unknown
CVE-2014-4984
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
Déjà Vu Crescendo Sales CRM has remote SQL Injection
0
Attacker Value
Unknown
CVE-2019-18804
Disclosure Date: November 07, 2019 (last updated November 08, 2023)
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
0
Attacker Value
Unknown
CVE-2005-2354
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.
0
Attacker Value
Unknown
CVE-2013-1391
Disclosure Date: October 30, 2019 (last updated November 27, 2024)
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.
0
Attacker Value
Unknown
CVE-2019-15494
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
0