Show filters
803 Total Results
Displaying 201-210 of 803
Sort by:
Attacker Value
Unknown
CVE-2022-3738
Disclosure Date: January 19, 2023 (last updated February 24, 2025)
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.
0
Attacker Value
Unknown
CVE-2023-21856
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSetup accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
0
Attacker Value
Unknown
CVE-2023-21842
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
0
Attacker Value
Unknown
CVE-2023-21837
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
0
Attacker Value
Unknown
CVE-2022-46732
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.
0
Attacker Value
Unknown
CVE-2022-42277
Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
0
Attacker Value
Unknown
CVE-2022-42276
Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
0
Attacker Value
Unknown
CVE-2022-42275
Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.
0
Attacker Value
Unknown
CVE-2022-46463
Disclosure Date: January 13, 2023 (last updated February 24, 2025)
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
0
Attacker Value
Unknown
CVE-2023-21743
Disclosure Date: January 10, 2023 (last updated February 24, 2025)
Microsoft SharePoint Server Security Feature Bypass Vulnerability
0