Show filters
215 Total Results
Displaying 31-40 of 215
Sort by:
Attacker Value
Unknown

CVE-2023-39425

Disclosure Date: February 14, 2024 (last updated October 25, 2024)
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-35062

Disclosure Date: February 14, 2024 (last updated October 30, 2024)
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-25073

Disclosure Date: February 14, 2024 (last updated October 30, 2024)
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2023-40266

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
Attacker Value
Unknown

CVE-2023-40265

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
Attacker Value
Unknown

CVE-2023-6985

Disclosure Date: February 05, 2024 (last updated February 14, 2024)
The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins that can be used to gain further access to a compromised site.
Attacker Value
Unknown

CVE-2023-49471

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-35867

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Attacker Value
Unknown

CVE-2023-50715

Disclosure Date: December 15, 2023 (last updated December 28, 2023)
Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch for this issue. When starting the Home Assistant 2023.12 release, the login page returns all currently active user accounts to browsing requests from the Local Area Network. Tests showed that this occurs when the request is not authenticated and the request originated locally, meaning on the Home Assistant host local subnet or any other private subnet. The rationale behind this is to make the login more user-friendly and an experience better aligned with other applications that have multiple user-profiles. However, as a result, all accounts are displayed regardless of them having logged in or not and for any device that navigates to the server. This disclosure is mitigated by the fact that it only occurs for requests originating from a LAN…
Attacker Value
Unknown

CVE-2023-47440

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.