Show filters
276 Total Results
Displaying 71-80 of 276
Sort by:
Attacker Value
Unknown
CVE-2023-6318
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.
Full versions and TV models affected:
* webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
* webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
* webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA
0
Attacker Value
Unknown
CVE-2023-6317
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.
Full versions and TV models affected:
webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA
webOS 5.5.0 - 04.50.51 running on OLED55CXPUA
webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB
webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA
0
Attacker Value
Unknown
CVE-2023-6047
Disclosure Date: March 29, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Algoritim E-commerce Software allows Reflected XSS.This issue affects E-commerce Software: before 3.9.2.
0
Attacker Value
Unknown
CVE-2024-2863
Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
0
Attacker Value
Unknown
CVE-2024-2862
Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
0
Attacker Value
Unknown
CVE-2024-0821
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-1886
Disclosure Date: February 26, 2024 (last updated March 05, 2024)
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
0
Attacker Value
Unknown
CVE-2024-1885
Disclosure Date: February 26, 2024 (last updated March 05, 2024)
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
0
Attacker Value
Unknown
CVE-2023-46596
Disclosure Date: February 15, 2024 (last updated January 24, 2025)
Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)
0
Attacker Value
Unknown
CVE-2023-6503
Disclosure Date: January 29, 2024 (last updated February 03, 2024)
The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
0