Show filters
107 Total Results
Displaying 31-40 of 107
Sort by:
Attacker Value
Unknown

CVE-2024-2863

Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
0
Attacker Value
Unknown

CVE-2024-2862

Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
0
Attacker Value
Unknown

CVE-2024-28171

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.
0
Attacker Value
Unknown

CVE-2024-28045

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Improper neutralization of input within the affected product could lead to cross-site scripting.
0
Attacker Value
Unknown

CVE-2024-28040

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_astListParameters.
0
Attacker Value
Unknown

CVE-2024-25567

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.
0
Attacker Value
Unknown

CVE-2024-23975

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_slogListParameters.
0
Attacker Value
Unknown

CVE-2024-23494

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_unListParameters.
0
Attacker Value
Unknown

CVE-2024-28891

Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in the script Handler_CFG.ashx.
0
Attacker Value
Unknown

CVE-2024-27303

Disclosure Date: March 06, 2024 (last updated March 07, 2024)
electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located before searching `PATH`. This means that if an attacker can place a malicious executable file named cmd.exe in the same folder as the installer, the installer will run the malicious file. Version 24.13.2 fixes this issue. No known workaround exists. The code executes at the installer-level before the app is present on the system, so there's no way to check if it exists in a current installer.
0