Show filters
819 Total Results
Displaying 141-150 of 819
Sort by:
Attacker Value
Unknown
CVE-2022-27539
Disclosure Date: June 12, 2023 (last updated February 25, 2025)
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
0
Attacker Value
Unknown
CVE-2023-3142
Disclosure Date: June 07, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0.
0
Attacker Value
Unknown
CVE-2022-48188
Disclosure Date: June 05, 2023 (last updated February 25, 2025)
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-48181
Disclosure Date: June 05, 2023 (last updated February 25, 2025)
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-45938
Disclosure Date: June 02, 2023 (last updated February 25, 2025)
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
0
Attacker Value
Unknown
CVE-2023-25440
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
0
Attacker Value
Unknown
CVE-2023-31475
Disclosure Date: May 11, 2023 (last updated February 24, 2025)
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.
0
Attacker Value
Unknown
CVE-2023-31473
Disclosure Date: May 11, 2023 (last updated February 24, 2025)
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.
0
Attacker Value
Unknown
CVE-2023-31477
Disclosure Date: May 11, 2023 (last updated February 24, 2025)
A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.
0
Attacker Value
Unknown
CVE-2023-31471
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the filesystem, the package list, or a URL.
0