Show filters
109 Total Results
Displaying 1-10 of 109
Sort by:
Attacker Value
Unknown

CVE-2023-31361

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown

CVE-2023-31360

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown

CVE-2024-13040

Disclosure Date: December 31, 2024 (last updated January 02, 2025)
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.
Attacker Value
Unknown

CVE-2024-9982

Disclosure Date: October 15, 2024 (last updated January 06, 2025)
AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.
0
Attacker Value
Unknown

CVE-2024-8863

Disclosure Date: September 14, 2024 (last updated September 21, 2024)
A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-45790

Disclosure Date: September 11, 2024 (last updated September 19, 2024)
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords, which could lead to gain unauthorized access and compromise other user accounts.
Attacker Value
Unknown

CVE-2024-45789

Disclosure Date: September 11, 2024 (last updated September 19, 2024)
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API endpoint used during the registration process. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body on the vulnerable application. Successful exploitation of this vulnerability could allow the attacker to bypass certain constraints in the registration process leading to creation of multiple accounts.
Attacker Value
Unknown

CVE-2024-45788

Disclosure Date: September 11, 2024 (last updated September 19, 2024)
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/flooding on the targeted system.
Attacker Value
Unknown

CVE-2024-45787

Disclosure Date: September 11, 2024 (last updated September 19, 2024)
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL and intercepting response of the API request leading to exposure of sensitive information belonging to other users.
Attacker Value
Unknown

CVE-2024-45786

Disclosure Date: September 11, 2024 (last updated September 19, 2024)
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to gain unauthorized access to sensitive information belonging to other users.