Show filters
1,869 Total Results
Displaying 71-80 of 1,869
Sort by:
Attacker Value
Unknown

CVE-2022-46403

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
Attacker Value
Unknown

CVE-2022-46402

Disclosure Date: December 19, 2022 (last updated February 24, 2025)
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.
Attacker Value
Unknown

CVE-2022-46401

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
Attacker Value
Unknown

CVE-2022-46400

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
Attacker Value
Unknown

CVE-2022-46399

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.
Attacker Value
Unknown

CVE-2022-46154

Disclosure Date: December 06, 2022 (last updated February 24, 2025)
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been addressed in version 4.50. Users are advised to upgrade. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2022-40772

Disclosure Date: November 23, 2022 (last updated October 08, 2023)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
Attacker Value
Unknown

CVE-2022-40771

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
Attacker Value
Unknown

CVE-2022-43426

Disclosure Date: October 19, 2022 (last updated October 25, 2023)
Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.
Attacker Value
Unknown

CVE-2022-40358

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafted svg file upload.