Search

Search Results (360621 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-43501 1 Elwsc 4 Kasago Ipv4, Kasago Ipv4 Light, Kasago Ipv6\/v4 Dual and 1 more 2025-03-24 9.1 Critical
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future ones.
CVE-2023-0759 1 Agentejo 1 Cockpit 2025-03-24 8.8 High
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
CVE-2022-21940 1 Johnsoncontrols 1 Metasys System Configuration Tool 2025-03-24 7.5 High
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
CVE-2022-34449 1 Dell 1 Powerpath Management Appliance 2025-03-24 6 Medium
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application.
CVE-2022-34450 1 Dell 1 Powerpath Management Appliance 2025-03-24 6.7 Medium
PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root.
CVE-2022-34451 1 Dell 1 Powerpath Management Appliance 2025-03-24 4.8 Medium
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server.
CVE-2019-15839 1 Sinaextra 1 Sina Extension For Elementor 2025-03-24 N/A
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
CVE-2022-45104 1 Dell 3 Evasa Provider Virtual Appliance, Solutions Enabler Virtual Appliance, Unisphere For Powermax Virtual Appliance 2025-03-24 8.8 High
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system.
CVE-2022-46675 1 Dell 1 Wyse Management Suite 2025-03-24 5.3 Medium
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research.
CVE-2022-46676 1 Dell 1 Wyse Management Suite 2025-03-24 4.9 Medium
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized.
CVE-2022-46678 1 Dell 1 Wyse Management Suite 2025-03-24 4.9 Medium
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
CVE-2022-46677 1 Dell 1 Wyse Management Suite 2025-03-24 6.8 Medium
Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.
CVE-2022-46755 1 Dell 1 Wyse Management Suite 2025-03-24 4.9 Medium
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
CVE-2023-0776 1 Baicells 8 Neutrino 430, Neutrino 430 Firmware, Nova430e and 5 more 2025-03-24 8.1 High
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce. 
CVE-2023-0780 1 Agentejo 1 Cockpit 2025-03-24 5.4 Medium
Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
CVE-2023-0786 1 Phpmyfaq 1 Phpmyfaq 2025-03-24 8.4 High
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2023-0787 1 Phpmyfaq 1 Phpmyfaq 2025-03-24 8.1 High
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
CVE-2024-55009 1 Datax 1 Autobib 2025-03-24 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter.
CVE-2024-31817 1 Totolink 2 Ex200, Ex200 Firmware 2025-03-24 7.5 High
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
CVE-2024-1589 1 Pressified 1 Sendpress 2025-03-24 6.1 Medium
The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)