Show filters
219 Total Results
Displaying 1-10 of 219
Sort by:
Attacker Value
Moderate

CVE-2019-17519

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.
Attacker Value
Moderate

CVE-2019-17060

Disclosure Date: February 10, 2020 (last updated February 21, 2025)
The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes certain memory contents upon receiving a packet with a Link Layer ID (LLID) equal to zero. This allows attackers within radio range to cause deadlocks, cause anomalous behavior in the BLE state machine, or trigger a buffer overflow via a crafted BLE Link Layer frame.
Attacker Value
Unknown

CVE-2025-23406

Disclosure Date: February 14, 2025 (last updated February 14, 2025)
Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP Network Series, which may lead to processing a specially crafted packet to cause the affected product crashed.
0
Attacker Value
Unknown

CVE-2025-1144

Disclosure Date: February 11, 2025 (last updated February 11, 2025)
School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as plaintext administrator credentials.
0
Attacker Value
Unknown

CVE-2024-49368

Disclosure Date: October 21, 2024 (last updated November 07, 2024)
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.
Attacker Value
Unknown

CVE-2024-49367

Disclosure Date: October 21, 2024 (last updated November 08, 2024)
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue.
Attacker Value
Unknown

CVE-2024-49366

Disclosure Date: October 21, 2024 (last updated November 08, 2024)
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26 fixes the issue.
Attacker Value
Unknown

CVE-2024-7269

Disclosure Date: August 28, 2024 (last updated September 20, 2024)
Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An attacker might inject a script to be run in user's browser. After multiple attempts to contact the vendor we did not receive any answer. The finder provided the information that this issue affects ESP HR Management versions before 6.6.
Attacker Value
Unknown

CVE-2024-2319

Disclosure Date: March 08, 2024 (last updated March 09, 2024)
Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality due to lack of proper sanitisation of JavaScript elements.
0
Attacker Value
Unknown

CVE-2024-24215

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request.