Show filters
171 Total Results
Displaying 51-60 of 171
Sort by:
Attacker Value
Unknown

CVE-2022-39055

Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
Attacker Value
Unknown

CVE-2022-42067

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
Attacker Value
Unknown

CVE-2022-42071

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
Attacker Value
Unknown

CVE-2022-42070

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
Attacker Value
Unknown

CVE-2022-42069

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2021-46837

Disclosure Date: August 30, 2022 (last updated November 29, 2024)
res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port in a response to a T.38 re-invite initiated by Asterisk. This is a re-occurrence of the CVE-2019-15297 symptoms but not for exactly the same reason. The crash occurs because there is an append operation relative to the active topology, but this should instead be a replace operation.
Attacker Value
Unknown

CVE-2022-2393

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.
Attacker Value
Unknown

CVE-2022-31770

Disclosure Date: July 04, 2022 (last updated October 07, 2023)
IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial of service by creating a specially crafted request. IBM X-Force ID: 228221.
Attacker Value
Unknown

CVE-2022-29005

Disclosure Date: May 23, 2022 (last updated November 15, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.
Attacker Value
Unknown

CVE-2021-3897

Disclosure Date: April 22, 2022 (last updated October 07, 2023)
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.