Show filters
177 Total Results
Displaying 51-60 of 177
Sort by:
Attacker Value
Unknown

CVE-2023-43567

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2020-36751

Disclosure Date: October 20, 2023 (last updated October 28, 2023)
The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_meta() function. This makes it possible for unauthenticated attackers to save meta fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2020-27636

Disclosure Date: October 10, 2023 (last updated October 14, 2023)
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
Attacker Value
Unknown

CVE-2022-3431

Disclosure Date: October 09, 2023 (last updated October 14, 2023)
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Attacker Value
Unknown

CVE-2023-43981

Disclosure Date: October 05, 2023 (last updated October 09, 2023)
Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.
Attacker Value
Unknown

CVE-2023-43980

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.
Attacker Value
Unknown

CVE-2023-40758

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Attacker Value
Unknown

CVE-2022-3746

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
Attacker Value
Unknown

CVE-2022-3745

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI.
Attacker Value
Unknown

CVE-2022-3744

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.