Show filters
645 Total Results
Displaying 121-130 of 645
Sort by:
Attacker Value
Unknown
CVE-2024-23730
Disclosure Date: January 21, 2024 (last updated January 30, 2024)
The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.
0
Attacker Value
Unknown
CVE-2024-22409
Disclosure Date: January 16, 2024 (last updated January 26, 2024)
DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user's profile information. The default privileges gave too many broad permissions to low privileged users. These have been constrained in PR #9067 to prevent abuse. This issue can result in privilege escalation for lower privileged users up to admin privileges, potentially, if a group with admin privileges exists. May not impact instances that have modified default privileges. This issue has been addressed in datahub version 0.12.1. Users are advised to upgrade.
0
Attacker Value
Unknown
CVE-2023-7154
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2023-6944
Disclosure Date: January 04, 2024 (last updated April 25, 2024)
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.
0
Attacker Value
Unknown
CVE-2023-43511
Disclosure Date: January 02, 2024 (last updated January 09, 2024)
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
0
Attacker Value
Unknown
CVE-2023-33033
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
Memory corruption in Audio during playback with speaker protection.
0
Attacker Value
Unknown
CVE-2023-33030
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
Memory corruption in HLOS while running playready use-case.
0
Attacker Value
Unknown
CVE-2023-28586
Disclosure Date: December 05, 2023 (last updated December 13, 2023)
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
0
Attacker Value
Unknown
CVE-2023-28546
Disclosure Date: December 05, 2023 (last updated December 12, 2023)
Memory Corruption in SPS Application while exporting public key in sorter TA.
0
Attacker Value
Unknown
CVE-2023-25057
Disclosure Date: November 30, 2023 (last updated December 07, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Libsyn Libsyn Publisher Hub.This issue affects Libsyn Publisher Hub: from n/a through 1.3.2.
0