Show filters
209 Total Results
Displaying 1-10 of 209
Sort by:
Attacker Value
Unknown

CVE-2024-9933

Disclosure Date: October 26, 2024 (last updated October 26, 2024)
The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login' function. This makes it possible for unauthenticated attackers to log in to the WatchTowerHQ client administrator user.
0
Attacker Value
Unknown

CVE-2023-43078

Disclosure Date: August 28, 2024 (last updated December 20, 2024)
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
Attacker Value
Unknown

CVE-2024-8105

Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown

CVE-2024-38483

Disclosure Date: August 14, 2024 (last updated September 19, 2024)
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
Attacker Value
Unknown

CVE-2024-6727

Disclosure Date: July 29, 2024 (last updated July 30, 2024)
A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionality of the application.
0
Attacker Value
Unknown

CVE-2023-32471

Disclosure Date: July 24, 2024 (last updated September 12, 2024)
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits.
Attacker Value
Unknown

CVE-2024-0158

Disclosure Date: July 02, 2024 (last updated August 01, 2024)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
Attacker Value
Unknown

CVE-2024-22429

Disclosure Date: May 17, 2024 (last updated January 31, 2025)
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2023-25701

Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.
0
Attacker Value
Unknown

CVE-2024-22448

Disclosure Date: April 10, 2024 (last updated February 05, 2025)
Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.