Search Results (359893 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-28392 1 Inaba 8 Ac-wapu-300, Ac-wapu-300-p, Ac-wapu-300-p Firmware and 5 more 2025-01-17 7.2 High
Wi-Fi AP UNIT AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and earlier, AC-WAPU-300 v1.00_B07 and earlier, AC-WAPU-300-P v1.00_B08P and earlier, AC-WAPUM-300 v1.00_B07 and earlier, and AC-WAPUM-300-P v1.00_B08P and earlier allow an authenticated user with an administrative privilege to execute an arbitrary OS command.
CVE-2023-28390 1 Icom 4 Sr-7100vn, Sr-7100vn\#31, Sr-7100vn\#31 Firmware and 1 more 2025-01-17 6.8 Medium
Privilege escalation vulnerability in SR-7100VN firmware Ver.1.38(N) and earlier and SR-7100VN #31 firmware Ver.1.21 and earlier allows a network-adjacent attacker with administrative privilege of the affected product to obtain an administrative privilege of the OS (Operating System). As a result, an arbitrary OS command may be executed.
CVE-2023-28367 1 Vektor-inc 1 Vk All In One Expansion Unit 2025-01-17 5.4 Medium
Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-27926 1 Vektor-inc 1 Vk All In One Expansion Unit 2025-01-17 5.4 Medium
Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-27925 1 Vektor-inc 1 Vk Blocks 2025-01-17 5.4 Medium
Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-27923 1 Vektor-inc 1 Vk Blocks 2025-01-17 5.4 Medium
Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2022-46286 1 Visam 1 Vbase Automation Base 2025-01-17 5.5 Medium
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
CVE-2023-52710 1 Huawei 3 Curiem-wfg9b, Curiem-wfg9b Firmware, Curiem Wfg98 Bios 2025-01-17 7.8 High
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap with the beginning SMRAM.This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.
CVE-2023-52547 1 Huawei 2 Curiem-wfg9b, Curiem-wfg9b Firmware 2025-01-17 7.8 High
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to corrupt data structures stored at the beginning of SMRAM and can potentially lead to code execution in SMM.
CVE-2023-52548 1 Huawei 2 Curiem-wfg9b, Curiem-wfg9b Firmware 2025-01-17 7.8 High
Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leveraged by a malicious OS attacker to corrupt arbitrary SMRAM memory and, in turn, lead to code execution in SMM
CVE-2023-52711 1 Huawei 2 Curiem-wfg9b, Curiem-wfg9b Firmware 2025-01-17 7.8 High
Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM memory thus potentially leading code execution in SMM
CVE-2023-52712 1 Huawei 2 Curiem-wfg9b, Curiem-wfg9b Firmware 2025-01-17 7.8 High
Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place by previous UEFI phases to prevent direct access to the SPI flash. The second issue can be used to both leak and corrupt SMM memory, thus potentially leading code execution in SMM
CVE-2023-31826 1 Skyscreamer 1 Nevado Jms 2025-01-17 7.8 High
Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
CVE-2023-31814 1 Dlink 2 Dir-300, Dir-300 Firmware 2025-01-17 9.8 Critical
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
CVE-2023-31763 1 Agshome Smart Alarm Project 2 Agshome Smart Alarm, Agshome Smart Alarm Firmware 2025-01-17 7.5 High
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
CVE-2023-29169 1 Myscada 1 Mypro 2025-01-17 8.8 High
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
CVE-2023-29150 1 Myscada 1 Mypro 2025-01-17 8.8 High
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
CVE-2023-28655 1 Sauter-controls 2 Ey-as525f001, Ey-as525f001 Firmware 2025-01-17 5.4 Medium
A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users.
CVE-2023-28652 1 Sauter-controls 2 Ey-as525f001, Ey-as525f001 Firmware 2025-01-17 6.5 Medium
An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.
CVE-2023-28650 1 Sauter-controls 2 Ey-as525f001, Ey-as525f001 Firmware 2025-01-17 6.1 Medium
An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security context.