Vulnerabilities (CVE)

Filtered by CWE-284
Total 3455 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-4213 1 Redhat 1 Jboss Enterprise Application Platform 2025-04-11 6.4 MEDIUM N/A
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
CVE-2013-7293 1 Asus 1 Wl-330nul 2025-04-11 5.0 MEDIUM N/A
The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to instead access a DNS hostname that does not always resolve to 192.168.1.1, which makes it easier for remote attackers to hijack the configuration traffic by controlling the server associated with that hostname.
CVE-2012-2947 2 Debian, Digium 3 Debian Linux, Asterisk, Certified Asterisk 2025-04-11 2.6 LOW N/A
chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows remote attackers to cause a denial of service (daemon crash) by placing a call on hold.
CVE-2012-1327 1 Cisco 1 Ios 2025-04-11 6.1 MEDIUM N/A
dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (assertion failure and reboot) via 802.11 wireless traffic, as demonstrated by a video call from Apple iOS 5.0 on an iPhone 4S, aka Bug ID CSCtt94391.
CVE-2012-2351 2 Debian, Mahara 2 Debian Linux, Mahara 2025-04-11 5.0 MEDIUM N/A
The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.
CVE-2022-47634 1 Isode 1 M-link 2025-04-10 N/A 8.1 HIGH
M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867.
CVE-2024-37567 1 Infoblox 1 Nios 2025-04-10 N/A 9.1 CRITICAL
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
CVE-2024-37566 1 Infoblox 1 Nios 2025-04-10 N/A 9.8 CRITICAL
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
CVE-2022-47543 1 Siren 1 Investigate 2025-04-10 N/A 5.3 MEDIUM
An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.
CVE-2025-2973 1 Code-projects 1 College Management System 2025-04-10 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file /Admin/student.php. The manipulation of the argument profile_image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-24486 1 Silextechnology 2 Ds-600, Ds-600 Firmware 2025-04-10 N/A 9.1 CRITICAL
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.
CVE-2024-24487 1 Silextechnology 2 Ds-600, Ds-600 Firmware 2025-04-10 N/A 6.8 MEDIUM
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command.
CVE-2024-24485 1 Silextechnology 2 Ds-600, Ds-600 Firmware 2025-04-10 N/A 7.5 HIGH
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.
CVE-2025-28407 1 Ruoyi 1 Ruoyi 2025-04-09 N/A 8.8 HIGH
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
CVE-2025-28408 1 Ruoyi 1 Ruoyi 2025-04-09 N/A 9.8 CRITICAL
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
CVE-2025-28409 1 Ruoyi 1 Ruoyi 2025-04-09 N/A 8.8 HIGH
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
CVE-2025-28410 1 Ruoyi 1 Ruoyi 2025-04-09 N/A 9.8 CRITICAL
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
CVE-2025-28411 1 Ruoyi 1 Ruoyi 2025-04-09 N/A 9.8 CRITICAL
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
CVE-2025-28412 1 Ruoyi 1 Ruoyi 2025-04-09 N/A 9.8 CRITICAL
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
CVE-2025-28402 1 Ruoyi 1 Ruoyi 2025-04-09 N/A 9.8 CRITICAL
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter