Show filters
1,712 Total Results
Displaying 251-260 of 1,712
Sort by:
Attacker Value
Unknown
CVE-2023-2541
Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about the application such as versions, host names, or IP addresses. No personal information or application data was exposed.
0
Attacker Value
Unknown
CVE-2023-1158
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list.
0
Attacker Value
Unknown
CVE-2022-4815
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
0
Attacker Value
Unknown
CVE-2023-20161
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
0
Attacker Value
Unknown
CVE-2023-20157
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
0
Attacker Value
Unknown
CVE-2023-25771
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2023-31407
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2023-31406
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2023-31404
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2023-30741
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
0