Show filters
222 Total Results
Displaying 81-90 of 222
Sort by:
Attacker Value
Unknown

CVE-2021-27470

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27468

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
Attacker Value
Unknown

CVE-2021-27466

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27464

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
Attacker Value
Unknown

CVE-2021-27462

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27460

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk AssetCentre main server and all agent machines.
Attacker Value
Unknown

CVE-2021-41181

Disclosure Date: March 08, 2022 (last updated February 23, 2025)
Nextcloud talk is a self hosting messaging service. In versions prior to 12.3.0 the Nextcloud Android Talk application did not properly detect the lockscreen state when a call was incoming. If an attacker got physical access to the locked phone, and the victim received a phone call the attacker could gain access to the chat messages and files of the user. It is recommended that the Nextcloud Android Talk App is upgraded to 12.3.0. There are no known workarounds.
Attacker Value
Unknown

CVE-2021-41180

Disclosure Date: March 08, 2022 (last updated February 23, 2025)
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user interaction. This only affected users of the Android Talk client. It is recommended that the Nextcloud Talk App is upgraded to 12.1.2. There are no known workarounds.
Attacker Value
Unknown

CVE-2021-35380

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore).
Attacker Value
Unknown

CVE-2022-0539

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in Packagist ptrofimov/beanstalk_console prior to 1.7.14.