NA - CVE-2024-48971 - The Clinician Password and Serial Number...
The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it...
NA - CVE-2024-48973 - The debug port on the ventilator's serial...
The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug port (which are unencrypted; see 3.2.1) that...
NA - CVE-2024-48974 - The ventilator does not perform proper file...
The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration...
NA - CVE-2024-50968 - A business logic vulnerability exists in the...
A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when...
High - CVE-2022-2232 - A flaw was found in the Keycloak package. This...
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
NA - CVE-2024-11210 - A vulnerability was found in EyouCMS 1.51. It...
A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the...