Show filters
3,317 Total Results
Displaying 401-410 of 3,317
Sort by:
Attacker Value
Unknown
CVE-2023-36618
Disclosure Date: October 04, 2023 (last updated February 25, 2025)
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users.
0
Attacker Value
Unknown
CVE-2023-3971
Disclosure Date: October 04, 2023 (last updated February 25, 2025)
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
0
Attacker Value
Unknown
CVE-2023-20268
Disclosure Date: September 27, 2023 (last updated February 25, 2025)
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.
This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A sustained attack could lead to the disruption of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel and intermittent loss of wireless client traffic.
0
Attacker Value
Unknown
CVE-2023-35793
Disclosure Date: September 27, 2023 (last updated February 25, 2025)
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.
0
Attacker Value
Unknown
CVE-2023-4915
Disclosure Date: September 13, 2023 (last updated November 09, 2023)
The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the user's password after providing the email. The new password is only sent to the user's email, so the attacker does not have access to the new password.
0
Attacker Value
Unknown
CVE-2023-28831
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation.
This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially crafted certificate.
0
Attacker Value
Unknown
CVE-2022-4896
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Cyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages "PNTMEDIDAS", "PEDIR", "HAYDISCOA" or "SPOOLER". A complete denial of service can be achieved by sending multiple requests simultaneously on a core.
0
Attacker Value
Unknown
CVE-2022-48475
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could cause a Buffer Overflow when the adminitrator tries to accept or delete the print query created by the request.
0
Attacker Value
Unknown
CVE-2022-48474
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, causing a memory failure error that shuts down the process.
0
Attacker Value
Unknown
CVE-2023-4270
Disclosure Date: September 11, 2023 (last updated October 08, 2023)
The Min Max Control WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
0