Show filters
1,463 Total Results
Displaying 241-250 of 1,463
Sort by:
Attacker Value
Unknown

CVE-2023-28025

Disclosure Date: December 21, 2023 (last updated February 25, 2025)
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
Attacker Value
Unknown

CVE-2023-35867

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Attacker Value
Unknown

CVE-2023-49165

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins Client Dash allows Stored XSS.This issue affects Client Dash: from n/a through 2.2.1.
Attacker Value
Unknown

CVE-2023-45185

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.
Attacker Value
Unknown

CVE-2023-45182

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
Attacker Value
Unknown

CVE-2023-45184

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.
Attacker Value
Unknown

CVE-2023-50424

Disclosure Date: December 12, 2023 (last updated February 25, 2025)
SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Attacker Value
Unknown

CVE-2023-28871

Disclosure Date: December 09, 2023 (last updated February 25, 2025)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
Attacker Value
Unknown

CVE-2023-28870

Disclosure Date: December 09, 2023 (last updated February 25, 2025)
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
Attacker Value
Unknown

CVE-2023-28869

Disclosure Date: December 09, 2023 (last updated February 25, 2025)
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.