Show filters
754 Total Results
Displaying 161-170 of 754
Sort by:
Attacker Value
Unknown

CVE-2023-4614

Disclosure Date: September 04, 2023 (last updated February 25, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
Attacker Value
Unknown

CVE-2023-4613

Disclosure Date: September 04, 2023 (last updated February 25, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
Attacker Value
Unknown

CVE-2023-3667

Disclosure Date: August 21, 2023 (last updated October 08, 2023)
The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-39438

Disclosure Date: August 15, 2023 (last updated February 25, 2025)
A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons who signed them as well as custom fields the CLA requester had configured. In addition, an arbitrary authenticated user can update or delete the CLA-configuration for repositories or organizations using CLA-assistant. The stored access tokens for GitHub are not affected, as these are redacted from the API-responses.
Attacker Value
Unknown

CVE-2023-27515

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access.
Attacker Value
Unknown

CVE-2023-38752

Disclosure Date: August 09, 2023 (last updated February 25, 2025)
Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the attribute information of the poster that is set as"non-disclosure" in the system settings.
Attacker Value
Unknown

CVE-2023-38751

Disclosure Date: August 09, 2023 (last updated February 25, 2025)
Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization information of the information receiver that is set as "non-disclosure" in the information provision operation.
Attacker Value
Unknown

CVE-2023-34010

Disclosure Date: August 05, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in submodule of David Lingren Media Library Assistant plugin  <= 3.0.7 versions.
Attacker Value
Unknown

CVE-2023-26527

Disclosure Date: June 16, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
Attacker Value
Unknown

CVE-2023-32673

Disclosure Date: June 12, 2023 (last updated October 08, 2023)
Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.