Show filters
977 Total Results
Displaying 421-430 of 977
Sort by:
Attacker Value
Unknown
CVE-2023-2152
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-30512
Disclosure Date: April 12, 2023 (last updated February 24, 2025)
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret.
0
Attacker Value
Unknown
CVE-2023-1939
Disclosure Date: April 11, 2023 (last updated February 24, 2025)
No access control for the OTP key
on OTP entries
in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
0
Attacker Value
Unknown
CVE-2022-43946
Disclosure Date: April 11, 2023 (last updated February 24, 2025)
Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via writing data into a windows pipe.
0
Attacker Value
Unknown
CVE-2023-24626
Disclosure Date: April 08, 2023 (last updated February 24, 2025)
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
0
Attacker Value
Unknown
CVE-2022-43309
Disclosure Date: April 07, 2023 (last updated February 24, 2025)
Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.
0
Attacker Value
Unknown
CVE-2023-0944
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not correctly validate user permissions with respect to certain actions that can be performed by the user.
0
Attacker Value
Unknown
CVE-2023-0225
Disclosure Date: April 03, 2023 (last updated February 24, 2025)
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.
0
Attacker Value
Unknown
CVE-2022-43773
Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored procedures enabled.
0
Attacker Value
Unknown
CVE-2023-1516
Disclosure Date: March 28, 2023 (last updated February 24, 2025)
RoboDK versions 5.5.3 and prior contain an insecure permission
assignment to critical directories vulnerability, which could allow a
local user to escalate privileges and write files to the RoboDK process
and achieve code execution.
0