Show filters
480 Total Results
Displaying 81-90 of 480
Sort by:
Attacker Value
Unknown

CVE-2022-26977

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS.
Attacker Value
Unknown

CVE-2022-26976

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
Attacker Value
Unknown

CVE-2022-26975

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
Attacker Value
Unknown

CVE-2022-26974

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.
Attacker Value
Unknown

CVE-2022-26973

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
Attacker Value
Unknown

CVE-2022-26972

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
Attacker Value
Unknown

CVE-2022-26971

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.
Attacker Value
Unknown

CVE-2020-14496

Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
Attacker Value
Unknown

CVE-2022-26233

Disclosure Date: April 03, 2022 (last updated February 23, 2025)
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
Attacker Value
Unknown

CVE-2021-45117

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.