Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-7113

Disclosure Date: August 13, 2024 (last updated August 14, 2024)
If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down processing of Data I/O for the duration of the attack.
0
Attacker Value
Unknown

CVE-2023-1577

Disclosure Date: July 31, 2024 (last updated August 14, 2024)
A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2023-34982

Disclosure Date: November 15, 2023 (last updated December 09, 2023)
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
Attacker Value
Unknown

CVE-2023-33873

Disclosure Date: November 15, 2023 (last updated December 09, 2023)
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
Attacker Value
Unknown

CVE-2023-25496

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2021-3633

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.
Attacker Value
Unknown

CVE-2020-8326

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2020-8317

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.