Show filters
69 Total Results
Displaying 31-40 of 69
Sort by:
Attacker Value
Unknown
CVE-2024-23788
Disclosure Date: February 14, 2024 (last updated December 18, 2024)
Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.
0
Attacker Value
Unknown
CVE-2024-23787
Disclosure Date: February 14, 2024 (last updated January 04, 2025)
Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.
0
Attacker Value
Unknown
CVE-2024-23786
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
0
Attacker Value
Unknown
CVE-2024-23785
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.
0
Attacker Value
Unknown
CVE-2024-23784
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displayed on the management page of the affected product.
0
Attacker Value
Unknown
CVE-2024-23783
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.
0
Attacker Value
Unknown
CVE-2023-7077
Disclosure Date: February 05, 2024 (last updated February 15, 2024)
Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attacker execute remote code by sending unintended parameters in http request.
0
Attacker Value
Unknown
CVE-2023-48376
Disclosure Date: December 15, 2023 (last updated December 21, 2023)
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
0
Attacker Value
Unknown
CVE-2023-48375
Disclosure Date: December 15, 2023 (last updated December 21, 2023)
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.
0
Attacker Value
Unknown
CVE-2023-48374
Disclosure Date: December 15, 2023 (last updated December 22, 2023)
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive information.
0