Show filters
977 Total Results
Displaying 411-420 of 977
Sort by:
Attacker Value
Unknown
CVE-2021-40331
Disclosure Date: May 05, 2023 (last updated February 24, 2025)
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the ownership of the table in Hive when Apache Ranger Hive Plugin is enabled
This issue affects Apache Ranger Hive Plugin: from 2.0.0 through 2.3.0. Users are recommended to upgrade to version 2.4.0 or later.
0
Attacker Value
Unknown
CVE-2023-28068
Disclosure Date: May 05, 2023 (last updated February 24, 2025)
Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authenticated malicious user can potentially exploit this vulnerability leading to privilege escalation by writing to a protected directory when Dell Command Monitor is installed to a non-default path
0
Attacker Value
Unknown
CVE-2023-30399
Disclosure Date: May 04, 2023 (last updated February 24, 2025)
Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update package link via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2023-25438
Disclosure Date: May 04, 2023 (last updated February 24, 2025)
An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files.
0
Attacker Value
Unknown
CVE-2023-30943
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
0
Attacker Value
Unknown
CVE-2023-0834
Disclosure Date: April 28, 2023 (last updated February 24, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 before 8.1.
0
Attacker Value
Unknown
CVE-2023-0207
Disclosure Date: April 22, 2023 (last updated February 24, 2025)
NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.
0
Attacker Value
Unknown
CVE-2023-28123
Disclosure Date: April 19, 2023 (last updated February 24, 2025)
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.
0
Attacker Value
Unknown
CVE-2023-30606
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator can call arbitrary methods on the `SiteSetting` class, notably `#clear_cache!` and `#notify_changed!`, which when done on a multisite instance, can affect the entire cluster resulting in a denial of service. Users not running in multisite environments are not affected. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-22294
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
0