Show filters
222 Total Results
Displaying 1-10 of 222
Sort by:
Attacker Value
Moderate
CVE-2017-5715
Disclosure Date: January 04, 2018 (last updated November 26, 2024)
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
6
Attacker Value
High
CVE-2021-22707
Disclosure Date: July 21, 2021 (last updated February 23, 2025)
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.
1
Attacker Value
Unknown
CVE-2021-36323
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
1
Attacker Value
Unknown
CVE-2024-47238
Disclosure Date: December 12, 2024 (last updated February 05, 2025)
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-29126
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.
0
Attacker Value
Unknown
CVE-2023-29125
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
0
Attacker Value
Unknown
CVE-2023-29121
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
0
Attacker Value
Unknown
CVE-2023-29120
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.
0
Attacker Value
Unknown
CVE-2023-29119
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.
0
Attacker Value
Unknown
CVE-2023-29118
Disclosure Date: November 05, 2024 (last updated November 09, 2024)
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.
0