Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 537 538 539 540 541 542 543 544 545 546 [547] 548 549 550 551 552 553 554 555 556 557 ... Result(s) : 43430

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
9.8 2022-07-26 CVE-2022-30273 cve The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption ...
9.8 2022-07-26 CVE-2022-29958 cve JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading project...
9.8 2022-07-26 CVE-2022-29953 cve The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An atta...
9.1 2022-07-26 CVE-2022-29952 cve Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communicatio...
9.8 2022-07-25 CVE-2021-23451 cve The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
9.8 2022-07-25 CVE-2020-28446 cve The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
9.8 2022-07-25 CVE-2020-28447 cve This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
9.8 2022-07-25 CVE-2020-28461 cve This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the ap...
9.8 2022-07-25 CVE-2020-28462 cve This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the...
9.8 2022-07-25 CVE-2020-28471 cve This affects the package properties-reader before 2.2.0.
9.8 2022-07-25 CVE-2020-7677 cve This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval fu...
9.8 2022-07-25 CVE-2020-7678 cve This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “e...
9.8 2022-07-25 CVE-2021-23373 cve All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.
9.8 2022-07-25 CVE-2021-23397 cve All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.
9.8 2022-07-25 CVE-2022-34907 cve An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system ...
9.8 2022-07-25 CVE-2022-36444 cve An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 befor...
9.8 2022-07-25 CVE-2022-35649 cve The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution ri...
9.8 2022-07-25 CVE-2022-24083 cve Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
9.8 2022-07-25 CVE-2022-33965 cve Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin
9.8 2022-07-25 CVE-2022-36446 cve software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
Page(s) : 1 ... 537 538 539 540 541 542 543 544 545 546 [547] 548 549 550 551 552 553 554 555 556 557 ... Result(s) : 43430