Show filters
323 Total Results
Displaying 71-80 of 323
Sort by:
Attacker Value
Unknown
CVE-2022-46624
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in Online Graduate Tracer System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
0
Attacker Value
Unknown
CVE-2022-4889
Disclosure Date: January 15, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in visegripped Stracker. Affected by this vulnerability is the function getHistory of the file doc_root/public_html/stracker/api.php. The manipulation of the argument symbol/startDate/endDate leads to sql injection. The identifier of the patch is 63e1b040373ee5b6c7d1e165ecf5ae1603d29e0a. It is recommended to apply a patch to fix this issue. The identifier VDB-218377 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2016-15011
Disclosure Date: January 06, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse of the file dssp-client/src/main/java/be/e_contract/dssp/client/SignResponseVerifier.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.2 is able to address this issue. The identifier of the patch is ec4238349691ec66dd30b416ec6eaab02d722302. It is recommended to upgrade the affected component. The identifier VDB-217549 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2014-125046
Disclosure Date: January 06, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in Seiji42 cub-scout-tracker. This affects an unknown part of the file databaseAccessFunctions.js. The manipulation leads to sql injection. The patch is named b4bc1a328b1f59437db159f9d136d9ed15707e31. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217551.
0
Attacker Value
Unknown
CVE-2012-10003
Disclosure Date: January 03, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in ahmyi RivetTracker. This issue affects some unknown processing. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The patch is named f053c5cc2bc44269b0496b5f275e349928a92ef9. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217271.
0
Attacker Value
Unknown
CVE-2012-10002
Disclosure Date: January 03, 2023 (last updated February 24, 2025)
A vulnerability was found in ahmyi RivetTracker. It has been declared as problematic. Affected by this vulnerability is the function changeColor of the file css.php. The manipulation of the argument set_css leads to cross site scripting. The attack can be launched remotely. The patch is named 45a0f33876d58cb7e4a0f17da149e58fc893b858. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217267.
0
Attacker Value
Unknown
CVE-2021-35954
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, flash custom malicious firmware, and brick the device via the Serial Wire Debug (SWD) feature.
0
Attacker Value
Unknown
CVE-2021-35953
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device outage) via crafted choices of the last three bytes of a characteristic value.
0
Attacker Value
Unknown
CVE-2021-35952
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to change the time, date, and month via Bluetooth LE Characteristics on handle 0x0017.
0
Attacker Value
Unknown
CVE-2021-35951
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious firmware update via BLE and brick the device.
0