Show filters
252 Total Results
Displaying 81-90 of 252
Sort by:
Attacker Value
Unknown

CVE-2023-1863

Disclosure Date: April 14, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection.This issue affects Water Metering Software: before 23.04.06.
Attacker Value
Unknown

CVE-2023-23591

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
Attacker Value
Unknown

CVE-2021-36821

Disclosure Date: March 16, 2023 (last updated August 18, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11.
Attacker Value
Unknown

CVE-2023-23558

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.
Attacker Value
Unknown

CVE-2022-48258

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.
Attacker Value
Unknown

CVE-2022-48257

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
Attacker Value
Unknown

CVE-2014-125076

Disclosure Date: January 11, 2023 (last updated October 20, 2023)
A vulnerability was found in NoxxieNl Criminals. It has been classified as critical. Affected is an unknown function of the file ingame/roulette.php. The manipulation of the argument gambleMoney leads to sql injection. The patch is identified as 0a60b31271d4cbf8babe4be993d2a3a1617f0897. It is recommended to apply a patch to fix this issue. VDB-218022 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-4306

Disclosure Date: January 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in cronvel terminal-kit up to 2.1.7. Affected is an unknown function. The manipulation leads to inefficient regular expression complexity. Upgrading to version 2.1.8 is able to address this issue. The name of the patch is a2e446cc3927b559d0281683feb9b821e83b758c. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217620.
Attacker Value
Unknown

CVE-2022-30260

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.
Attacker Value
Unknown

CVE-2022-3792

Disclosure Date: December 19, 2022 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection.This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.