Show filters
1,765 Total Results
Displaying 271-280 of 1,765
Sort by:
Attacker Value
Unknown

CVE-2022-29262

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-27229

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-24379

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-46748

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.
Attacker Value
Unknown

CVE-2023-6103

Disclosure Date: November 13, 2023 (last updated February 25, 2025)
A vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /WiFi.html of the component SSID Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-245065 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-46947

Disclosure Date: November 03, 2023 (last updated February 25, 2025)
Subrion 4.2.1 has a remote command execution vulnerability in the backend.
Attacker Value
Unknown

CVE-2023-43875

Disclosure Date: October 19, 2023 (last updated February 25, 2025)
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.
Attacker Value
Unknown

CVE-2023-43884

Disclosure Date: September 28, 2023 (last updated February 25, 2025)
A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter.
Attacker Value
Unknown

CVE-2023-44216

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
Attacker Value
Unknown

CVE-2023-43830

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'.