Show filters
782 Total Results
Displaying 221-230 of 782
Sort by:
Attacker Value
Unknown
CVE-2023-0834
Disclosure Date: April 28, 2023 (last updated February 24, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 before 8.1.
0
Attacker Value
Unknown
CVE-2023-0207
Disclosure Date: April 22, 2023 (last updated February 24, 2025)
NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.
0
Attacker Value
Unknown
CVE-2023-28123
Disclosure Date: April 19, 2023 (last updated February 24, 2025)
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.
0
Attacker Value
Unknown
CVE-2023-30606
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator can call arbitrary methods on the `SiteSetting` class, notably `#clear_cache!` and `#notify_changed!`, which when done on a multisite instance, can affect the entire cluster resulting in a denial of service. Users not running in multisite environments are not affected. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-22294
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
0
Attacker Value
Unknown
CVE-2023-2152
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-30512
Disclosure Date: April 12, 2023 (last updated February 24, 2025)
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
0
Attacker Value
Unknown
CVE-2023-1939
Disclosure Date: April 11, 2023 (last updated February 24, 2025)
No access control for the OTP key
on OTP entries
in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
0
Attacker Value
Unknown
CVE-2022-43946
Disclosure Date: April 11, 2023 (last updated February 24, 2025)
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.
0
Attacker Value
Unknown
CVE-2023-24626
Disclosure Date: April 08, 2023 (last updated February 24, 2025)
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
0