Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2023-4617
Disclosure Date: December 19, 2024 (last updated December 19, 2024)
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.
This issue affects Govee Home applications on Android and iOS in versions before 5.9.
0
Attacker Value
Unknown
CVE-2024-22048
Disclosure Date: January 04, 2024 (last updated January 12, 2024)
govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.
0
Attacker Value
Unknown
CVE-2023-6341
Disclosure Date: November 30, 2023 (last updated December 09, 2023)
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.
0
Attacker Value
Unknown
CVE-2023-47655
Disclosure Date: November 18, 2023 (last updated November 28, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara: from n/a through 7.5.
0
Attacker Value
Unknown
CVE-2023-45956
Disclosure Date: October 30, 2023 (last updated November 07, 2023)
An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.
0
Attacker Value
Unknown
CVE-2023-44689
Disclosure Date: October 11, 2023 (last updated October 18, 2023)
e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack.
0
Attacker Value
Unknown
CVE-2023-42189
Disclosure Date: October 10, 2023 (last updated February 16, 2024)
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
0
Attacker Value
Unknown
CVE-2023-3612
Disclosure Date: September 11, 2023 (last updated October 08, 2023)
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.
0
Attacker Value
Unknown
CVE-2022-31215
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach Server before 3.70.1, and Reach Client Agents before 10.1.11.
0
Attacker Value
Unknown
CVE-2021-43284
Disclosure Date: November 30, 2021 (last updated February 23, 2025)
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).
0