Show filters
726 Total Results
Displaying 111-120 of 726
Sort by:
Attacker Value
Unknown

CVE-2023-20071

Disclosure Date: November 01, 2023 (last updated February 25, 2025)
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this vulnerability by sending crafted FTP traffic through an affected device. A successful exploit could allow the attacker to bypass FTP inspection and deliver a malicious payload.
Attacker Value
Unknown

CVE-2023-4608

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-4607

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
An authenticated XCC user can change permissions for any user through a crafted API command.
Attacker Value
Unknown

CVE-2023-4606

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-5017

Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability was found in lmxcms up to 1.41. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin.php. The manipulation of the argument lid leads to sql injection. VDB-239858 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-32461

Disclosure Date: September 15, 2023 (last updated February 25, 2025)
Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, leading to corrupt memory and potentially escalate privileges.  
Attacker Value
Unknown

CVE-2023-39983

Disclosure Date: September 02, 2023 (last updated February 25, 2025)
A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web application.
Attacker Value
Unknown

CVE-2023-39982

Disclosure Date: September 02, 2023 (last updated February 25, 2025)
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.
Attacker Value
Unknown

CVE-2023-39981

Disclosure Date: September 02, 2023 (last updated February 25, 2025)
A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker.
Attacker Value
Unknown

CVE-2023-39980

Disclosure Date: September 02, 2023 (last updated February 25, 2025)
A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands.