Show filters
754 Total Results
Displaying 161-170 of 754
Sort by:
Attacker Value
Unknown
CVE-2023-4614
Disclosure Date: September 04, 2023 (last updated February 25, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
0
Attacker Value
Unknown
CVE-2023-4613
Disclosure Date: September 04, 2023 (last updated February 25, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
0
Attacker Value
Unknown
CVE-2023-3667
Disclosure Date: August 21, 2023 (last updated October 08, 2023)
The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2023-39438
Disclosure Date: August 15, 2023 (last updated February 25, 2025)
A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons who signed them as well as custom fields the CLA requester had configured. In addition, an arbitrary authenticated user can update or delete the CLA-configuration for repositories or organizations using CLA-assistant. The stored access tokens for GitHub are not affected, as these are redacted from the API-responses.
0
Attacker Value
Unknown
CVE-2023-27515
Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access.
0
Attacker Value
Unknown
CVE-2023-38752
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the attribute information of the poster that is set as"non-disclosure" in the system settings.
0
Attacker Value
Unknown
CVE-2023-38751
Disclosure Date: August 09, 2023 (last updated February 25, 2025)
Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization information of the information receiver that is set as "non-disclosure" in the information provision operation.
0
Attacker Value
Unknown
CVE-2023-34010
Disclosure Date: August 05, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in submodule of David Lingren Media Library Assistant plugin <= 3.0.7 versions.
0
Attacker Value
Unknown
CVE-2023-26527
Disclosure Date: June 16, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
0
Attacker Value
Unknown
CVE-2023-32673
Disclosure Date: June 12, 2023 (last updated October 08, 2023)
Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.
0