Show filters
177 Total Results
Displaying 61-70 of 177
Sort by:
Attacker Value
Unknown

CVE-2022-3743

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands.
Attacker Value
Unknown

CVE-2022-3742

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.
Attacker Value
Unknown

CVE-2023-36313

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed".
Attacker Value
Unknown

CVE-2023-36311

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
Attacker Value
Unknown

CVE-2023-36310

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
Attacker Value
Unknown

CVE-2023-36309

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.
Attacker Value
Unknown

CVE-2022-48181

Disclosure Date: June 05, 2023 (last updated October 08, 2023)
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
Attacker Value
Unknown

CVE-2023-33971

Disclosure Date: May 31, 2023 (last updated October 08, 2023)
Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. A probable stored cross-site scripting vulnerability is present in Formcreator 2.13.5 and prior via the use of the use of `##FULLFORM##` for rendering. This could result in arbitrary javascript code execution in an admin/tech context. A patch is unavailable as of time of publication. As a workaround, one may use a regular expression to remove `< > "` in all fields.
Attacker Value
Unknown

CVE-2023-25755

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a specially crafted project file, information may be disclosed and/or arbitrary code may be executed.
Attacker Value
Unknown

CVE-2023-27762

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file.