Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
administrator vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-51989
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows malicious users to log in to administrator accounts with empty passwords.
Dlink Dir-822 Firmware 1.0.2
9.8
CVSSv3
CVE-2023-49238
In Gradle Enterprise prior to 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an a...
Gradle Enterprise
9.8
CVSSv3
CVE-2023-43742
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions before 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated malicious user to obtain an administrative session via a protection mechanism failure in the aut...
Zultys Mx-se Firmware
Zultys Mx-se Ii Firmware
Zultys Mx-e Firmware
Zultys Mx-virtual Firmware
Zultys Mx250 Firmware
Zultys Mx30 Firmware
9.8
CVSSv3
CVE-2023-47207
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated malicious user to execute code with local administrator privileges.
Deltaww Infrasuite Device Master 1.0.7
9.8
CVSSv3
CVE-2023-23324
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 exists to contain hardcoded credentials for the Administrator account.
Zumtobel Netlink Ccd Firmware 3.80
9.8
CVSSv3
CVE-2023-4677
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an admini...
Artica Pandora Fms
9.8
CVSSv3
CVE-2023-43902
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated malicious users to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
Emsigner Emsigner 2.8.7
9.8
CVSSv3
CVE-2023-5719
The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to a device. If such a password contains the percent (%) character, invalid values will be included, po...
Redlion Crimson
Redlion Crimson 3.2
9.8
CVSSv3
CVE-2023-41351
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote malicious user to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote malicious us...
Nokia G-040w-q Firmware G040wqr201207
9.8
CVSSv3
CVE-2023-1719
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote malicious users to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP cod...
Bitrix24 Bitrix24 22.0.300
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »