βΌ CVE-2023-30718 βΌ
π Read
via "National Vulnerability Database".
Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.π Read
via "National Vulnerability Database".
βΌ CVE-2023-4485 βΌ
π Read
via "National Vulnerability Database".
ARDEREGΓ ?Sistema SCADA Central versions 2.203 and priorlogin page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the database. In this case, the vulnerability could allow an attacker to execute arbitrary SQL queries through the login page, potentially leading to unauthorized access, data leakage, or even disruption of critical industrial processes.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30720 βΌ
π Read
via "National Vulnerability Database".
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30713 βΌ
π Read
via "National Vulnerability Database".
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30717 βΌ
π Read
via "National Vulnerability Database".
Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30708 βΌ
π Read
via "National Vulnerability Database".
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30711 βΌ
π Read
via "National Vulnerability Database".
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.π Read
via "National Vulnerability Database".
βΌ CVE-2023-27950 βΌ
π Read
via "National Vulnerability Database".
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processing an image may result in disclosure of process memory.π Read
via "National Vulnerability Database".
βΌ CVE-2023-32379 βΌ
π Read
via "National Vulnerability Database".
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.4. An app may be able to execute arbitrary code with kernel privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30726 βΌ
π Read
via "National Vulnerability Database".
PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30719 βΌ
π Read
via "National Vulnerability Database".
Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certain message data.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29166 βΌ
π Read
via "National Vulnerability Database".
A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28187 βΌ
π Read
via "National Vulnerability Database".
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3. A user may be able to cause a denial-of-service.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30728 βΌ
π Read
via "National Vulnerability Database".
Intent redirection vulnerability in PackageInstallerCHN prior to version 13.1.03.00 allows local attacker to access arbitrary file. This vulnerability requires user interaction.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30729 βΌ
π Read
via "National Vulnerability Database".
Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40560 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <=Γ 5.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-4634 βΌ
π Read
via "National Vulnerability Database".
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40553 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Plausible.Io Plausible Analytics plugin <=Γ 1.3.3 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-32162 βΌ
π Read
via "National Vulnerability Database".
Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the handling of the WacomInstallI.txt file by the PrefUtil.exe utility. The issue results from incorrect permissions on the WacomInstallI.txt file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-16318.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29441 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <=Γ 3.5.8.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40554 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <=Γ 7.2.0 versions.π Read
via "National Vulnerability Database".