Show filters
1,987 Total Results
Displaying 371-380 of 1,987
Sort by:
Attacker Value
Unknown

CVE-2021-31937

Disclosure Date: June 28, 2023 (last updated March 01, 2025)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2023-34203

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
Attacker Value
Unknown

CVE-2023-29345

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2023-33143

Disclosure Date: June 03, 2023 (last updated October 08, 2023)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-25537

Disclosure Date: May 22, 2023 (last updated February 25, 2025)
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Attacker Value
Unknown

CVE-2021-46888

Disclosure Date: May 21, 2023 (last updated February 25, 2025)
An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an attacker to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with the atob function.
Attacker Value
Unknown

CVE-2023-30510

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data due to the network position of the Aruba EdgeConnect Enterprise instance.
Attacker Value
Unknown

CVE-2023-30509

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Attacker Value
Unknown

CVE-2023-30508

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Attacker Value
Unknown

CVE-2023-30507

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.