Show filters
818 Total Results
Displaying 201-210 of 818
Sort by:
Attacker Value
Unknown

CVE-2023-0608

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2.
Attacker Value
Unknown

CVE-2022-40137

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-40136

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-40135

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-40134

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-41613

Disclosure Date: January 06, 2023 (last updated February 24, 2025)
Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, which may allow an attacker to crash the product, disclose sensitive information, or execute arbitrary code.
Attacker Value
Unknown

CVE-2022-40201

Disclosure Date: January 06, 2023 (last updated February 24, 2025)
Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a malformed design (DGN) file is parsed. This may allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-4732

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
Attacker Value
Unknown

CVE-2022-4647

Disclosure Date: December 22, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.
Attacker Value
Unknown

CVE-2022-4617

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.