Show filters
469 Total Results
Displaying 141-150 of 469
Sort by:
Attacker Value
Unknown

CVE-2023-29161

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-29157

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-31078

Disclosure Date: November 10, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.4.1 versions.
Attacker Value
Unknown

CVE-2023-4632

Disclosure Date: November 08, 2023 (last updated February 25, 2025)
An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2023-3972

Disclosure Date: November 01, 2023 (last updated February 25, 2025)
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).
Attacker Value
Unknown

CVE-2023-4823

Disclosure Date: October 31, 2023 (last updated February 25, 2025)
The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.
Attacker Value
Unknown

CVE-2023-5116

Disclosure Date: October 31, 2023 (last updated November 07, 2023)
The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2022-3702

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions.
Attacker Value
Unknown

CVE-2022-3701

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.
Attacker Value
Unknown

CVE-2022-3700

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files.