Show filters
169 Total Results
Displaying 71-80 of 169
Sort by:
Attacker Value
Unknown
CVE-2022-33087
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2021-33615
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.
0
Attacker Value
Unknown
CVE-2022-30585
Disclosure Date: May 26, 2022 (last updated October 07, 2023)
The REST API in Archer Platform 6.x before 6.11 (6.11.0.0) contains an Authorization Bypass Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to view sensitive information. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.
0
Attacker Value
Unknown
CVE-2022-30584
Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.
0
Attacker Value
Unknown
CVE-2021-43454
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .
0
Attacker Value
Unknown
CVE-2021-33616
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.
0
Attacker Value
Unknown
CVE-2021-38362
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDOR) issue and retrieve sensitive data.
0
Attacker Value
Unknown
CVE-2022-26951
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.
0
Attacker Value
Unknown
CVE-2022-26950
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.
0
Attacker Value
Unknown
CVE-2022-26949
Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowed by extra privileges.
0