Show filters
140 Total Results
Displaying 71-80 of 140
Sort by:
Attacker Value
Unknown

CVE-2022-0986

Disclosure Date: March 16, 2022 (last updated February 23, 2025)
Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
Attacker Value
Unknown

CVE-2022-0752

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.
Attacker Value
Unknown

CVE-2022-0838

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.
Attacker Value
Unknown

CVE-2022-0753

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
Attacker Value
Unknown

CVE-2021-43693

Disclosure Date: November 29, 2021 (last updated February 23, 2025)
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
Attacker Value
Unknown

CVE-2021-3797

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
hestiacp is vulnerable to Use of Wrong Operator in String Comparison
Attacker Value
Unknown

CVE-2021-37160

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.
Attacker Value
Unknown

CVE-2021-37167

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.
Attacker Value
Unknown

CVE-2021-37164

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer overflow.
Attacker Value
Unknown

CVE-2021-37161

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution.