Show filters
788 Total Results
Displaying 191-200 of 788
Sort by:
Attacker Value
Unknown

CVE-2022-42277

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Attacker Value
Unknown

CVE-2022-42276

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Attacker Value
Unknown

CVE-2022-42275

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.
Attacker Value
Unknown

CVE-2022-46463

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Attacker Value
Unknown

CVE-2023-21743

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2022-45424

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface.
Attacker Value
Unknown

CVE-2022-45423

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).
Attacker Value
Unknown

CVE-2022-44013

Disclosure Date: December 25, 2022 (last updated February 24, 2025)
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because the password in a Credential Object is not checked.
Attacker Value
Unknown

CVE-2022-3188

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions completed by specific users.
Attacker Value
Unknown

CVE-2022-47377

Disclosure Date: December 16, 2022 (last updated February 24, 2025)
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 1.13.4 as soon as possible (available in SICK Support Portal).