Show filters
461 Total Results
Displaying 61-70 of 461
Sort by:
Attacker Value
Unknown

CVE-2023-3722

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
Attacker Value
Unknown

CVE-2023-3527

Disclosure Date: July 18, 2023 (last updated October 08, 2023)
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software such as Microsoft Excel.  
Attacker Value
Unknown

CVE-2020-20118

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.
Attacker Value
Unknown

CVE-2023-31187

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
Attacker Value
Unknown

CVE-2023-31186

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
Attacker Value
Unknown

CVE-2023-32218

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Attacker Value
Unknown

CVE-2023-1981

Disclosure Date: May 26, 2023 (last updated October 08, 2023)
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Attacker Value
Unknown

CVE-2023-30124

Disclosure Date: May 18, 2023 (last updated October 08, 2023)
LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2023-27238

Disclosure Date: May 12, 2023 (last updated February 24, 2025)
LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.
Attacker Value
Unknown

CVE-2023-27237

Disclosure Date: May 12, 2023 (last updated February 24, 2025)
LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.