Critical · CVSS 10
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.
Published May 13, 2021 · Updated Sep 17, 2024
Medium · CVSS 4.6
Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out Reflected XSS (Cross-site scripting) attacks, additionally access and manipulate customer’s information.
Published May 7, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.3
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.
Published May 20, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.3
The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows remote unauthenticated attackers can send a large number of valid usernames, and force those logged-in account to log out, causing the user to be unable to access the services
Published May 28, 2021 · Updated Sep 17, 2024
Medium · CVSS 6.5
Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file.
Published May 7, 2021 · Updated Sep 17, 2024
High · CVSS 7.8
Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.
Published May 18, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.4
IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015
Published May 20, 2021 · Updated Sep 17, 2024
Low · CVSS 3.3
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.
Published May 5, 2021 · Updated Sep 17, 2024
Low · CVSS 3.1
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918.
Published May 21, 2021 · Updated Sep 17, 2024
Critical · CVSS 9
IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.
Published May 31, 2021 · Updated Sep 17, 2024
Medium · CVSS 4.3
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199281.
Published May 10, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.3
IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system. IBM X-Force ID: 199398.
Published May 31, 2021 · Updated Sep 17, 2024
Critical · CVSS 9.1
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
Published May 25, 2022 · Updated Sep 17, 2024
Medium · CVSS 5.4
Special characters of IGT search function in igt+ are not filtered in specific fields, which allow remote authenticated attackers can inject malicious JavaScript and carry out DOM-based XSS (Cross-site scripting) attacks.
Published May 11, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.3
An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 ( 2022/02/16 ) and later
Published May 5, 2022 · Updated Sep 17, 2024
Medium · CVSS 4.9
HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Approved Applications in the Traveler administration web pages. An attacker could exploit this vulnerability to execute a malicious script to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site.
Published May 31, 2022 · Updated Sep 17, 2024
Medium · CVSS 5.3
IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.
Published May 20, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.1
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
Published May 24, 2021 · Updated Sep 17, 2024
Medium · CVSS 5.9
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.
Published May 17, 2021 · Updated Sep 17, 2024
Medium · CVSS 4.2
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
Published May 12, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.2
Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and perform unauthorized actions on the affected system.
Published May 21, 2021 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
Published May 11, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214619.
Published May 11, 2022 · Updated Sep 16, 2024
High · CVSS 7.5
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.
Published May 13, 2021 · Updated Sep 16, 2024
Medium · CVSS 6.8
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
Published May 25, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 200252.
Published May 20, 2021 · Updated Sep 16, 2024
High · CVSS 7.5
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
Published May 31, 2021 · Updated Sep 16, 2024
Medium · CVSS 5.3
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
Published May 27, 2022 · Updated Sep 16, 2024
High · CVSS 8.7
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.
Published May 26, 2021 · Updated Sep 16, 2024
Medium · CVSS 4
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.
Published May 31, 2021 · Updated Sep 16, 2024
Medium · CVSS 6.6
The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
Published May 27, 2022 · Updated Sep 16, 2024
Medium · CVSS 4.6
Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Stored Cross-site scripting) attacks, additionally access and manipulate customer’s information.
Published May 7, 2021 · Updated Sep 16, 2024
High · CVSS 7.6
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.
Published May 16, 2022 · Updated Sep 16, 2024
Medium · CVSS 4.7
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
Published May 6, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.3
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.
Published May 13, 2021 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.
Published May 10, 2022 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.
Published May 11, 2022 · Updated Sep 16, 2024
Medium · CVSS 6.1
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196017.
Published May 5, 2021 · Updated Sep 16, 2024
High · CVSS 7.1
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later
Published May 5, 2022 · Updated Sep 16, 2024
Medium · CVSS 6.5
An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, and QTS: QuTScloud c5.0.1.1998 and later QuTS hero h4.5.4.1971 build 20220310 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 4.3.4.1976 build 20220303 and later QTS 4.3.3.1945 build 20220303 and later QTS 4.2.6 build 20220304 and later QTS 4.3.6.1965 build 20220302 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and later
Published May 5, 2022 · Updated Sep 16, 2024
High · CVSS 7.3
Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Internet Security 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Smart Security Premium 11.2 versions prior to 15.1.12.0. ESET, spol. s r.o. ESET Endpoint Antivirus 6.0 versions prior to 9.0.2046.0; 6.0 versions prior to 8.1.2050.0; 6.0 versions prior to 8.0.2053.0. ESET, spol. s r.o. ESET Endpoint Security 6.0 versions prior to 9.0.2046.0; 6.0 versions prior to 8.1.2050.0; 6.0 versions prior to 8.0.2053.0. ESET, spol. s r.o. ESET Server Security for Microsoft Windows Server 8.0 versions prior to 9.0.12012.0. ESET, spol. s r.o. ESET File Security for Microsoft Windows Server 8.0.12013.0. ESET, spol. s r.o. ESET Mail Security for Microsoft Exchange Server 6.0 versions prior to 8.0.10020.0. ESET, spol. s r.o. ESET Mail Security for IBM Domino 6.0 versions prior to 8.0.14011.0. ESET, spol. s r.o. ESET Security for Microsoft SharePoint Server 6.0 versions prior to 8.0.15009.0.
Published May 11, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.3
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
Published May 13, 2021 · Updated Sep 16, 2024
High · CVSS 7.2
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 199184.
Published May 24, 2021 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.
Published May 12, 2022 · Updated Sep 16, 2024
Medium · CVSS 5.9
Type Confusion in 802154 ACK Frames Handling. Zephyr versions >= v2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-27r3-rxch-2hm7
Published May 24, 2021 · Updated Sep 16, 2024
Medium · CVSS 4.2
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when commands such as "saslStart", "saslContinue", "isMaster", "createUser", and "updateUser" are executed. Without due care, an application may inadvertently expose this authenticated-related information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C# Driver v2.12 versions prior to and including 2.12.1.
Published May 13, 2021 · Updated Sep 16, 2024
Medium · CVSS 6.5
The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.
Published May 28, 2021 · Updated Sep 16, 2024
High · CVSS 7.8
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
Published May 5, 2021 · Updated Sep 16, 2024
Medium · CVSS 6.5
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195522.
Published May 19, 2021 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
Published May 10, 2022 · Updated Sep 16, 2024