Show filters
810 Total Results
Displaying 211-220 of 810
Sort by:
Attacker Value
Unknown

CVE-2023-21837

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Attacker Value
Unknown

CVE-2022-46732

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.
Attacker Value
Unknown

CVE-2022-42277

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Attacker Value
Unknown

CVE-2022-42276

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.
Attacker Value
Unknown

CVE-2022-42275

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.
Attacker Value
Unknown

CVE-2022-46463

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."
Attacker Value
Unknown

CVE-2023-21743

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2022-45424

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface.
Attacker Value
Unknown

CVE-2022-45423

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).
Attacker Value
Unknown

CVE-2022-44013

Disclosure Date: December 25, 2022 (last updated February 24, 2025)
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because the password in a Credential Object is not checked.