Show filters
121 Total Results
Displaying 51-60 of 121
Sort by:
Attacker Value
Unknown

CVE-2022-43143

Disclosure Date: November 21, 2022 (last updated December 22, 2024)
A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.
Attacker Value
Unknown

CVE-2022-30877

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.
Attacker Value
Unknown

CVE-2022-30899

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
Attacker Value
Unknown

CVE-2022-30330

Disclosure Date: May 07, 2022 (last updated February 23, 2025)
In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operations. Using these flaws, malicious firmware code can elevate privileges, permanently make the device inoperable or overwrite the trusted bootloader code to compromise the hardware wallet across reboots or storage wipes.
Attacker Value
Unknown

CVE-2021-45783

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.
Attacker Value
Unknown

CVE-2021-39390

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter.
Attacker Value
Unknown

CVE-2022-26174

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injected into the display fields.
Attacker Value
Unknown

CVE-2022-0725

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
Attacker Value
Unknown

CVE-2022-23377

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.
Attacker Value
Unknown

CVE-2021-44225

Disclosure Date: November 26, 2021 (last updated February 23, 2025)
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property