Show filters
1,712 Total Results
Displaying 251-260 of 1,712
Sort by:
Attacker Value
Unknown

CVE-2023-2541

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about the application such as versions, host names, or IP addresses. No personal information or application data was exposed.
Attacker Value
Unknown

CVE-2023-1158

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 
Attacker Value
Unknown

CVE-2022-4815

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 
Attacker Value
Unknown

CVE-2023-20161

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
Attacker Value
Unknown

CVE-2023-20157

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
Attacker Value
Unknown

CVE-2023-25771

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2023-31407

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2023-31406

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2023-31404

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with specific privileges could have access to credentials of other users. It could let them access data sources which would otherwise be restricted.
Attacker Value
Unknown

CVE-2023-30741

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.