U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
There are 234,773 matching records.
Displaying matches 141 through 160.
Vuln ID Summary CVSS Severity
CVE-2023-43528

Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

Published: May 06, 2024; 11:15:20 AM -0400
V3.1: 6.1 MEDIUM
V2.0:(not available)
CVE-2023-43527

Information disclosure while parsing dts header atom in Video.

Published: May 06, 2024; 11:15:20 AM -0400
V3.1: 6.8 MEDIUM
V2.0:(not available)
CVE-2023-43526

Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

Published: May 06, 2024; 11:15:20 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-43525

Memory corruption while copying the sound model data from user to kernel buffer during sound model register.

Published: May 06, 2024; 11:15:20 AM -0400
V3.1: 6.7 MEDIUM
V2.0:(not available)
CVE-2023-43524

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

Published: May 06, 2024; 11:15:20 AM -0400
V3.1: 6.7 MEDIUM
V2.0:(not available)
CVE-2023-43521

Memory corruption when multiple listeners are being registered with the same file descriptor.

Published: May 06, 2024; 11:15:19 AM -0400
V3.1: 6.7 MEDIUM
V2.0:(not available)
CVE-2023-33119

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

Published: May 06, 2024; 11:15:19 AM -0400
V3.1: 8.4 HIGH
V2.0:(not available)
CVE-2024-4549

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

Published: May 06, 2024; 10:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-4548

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.

Published: May 06, 2024; 10:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-4547

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

Published: May 06, 2024; 10:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-33752

An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code.

Published: May 06, 2024; 10:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-33830

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

Published: May 06, 2024; 9:15:49 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-33829

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.

Published: May 06, 2024; 9:15:49 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-33788

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

Published: May 06, 2024; 9:15:49 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-33749

DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

Published: May 06, 2024; 9:15:49 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-3576

The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.

Published: May 06, 2024; 8:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-33753

Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization.

Published: May 06, 2024; 8:15:08 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-49676

An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.

Published: May 06, 2024; 8:15:08 AM -0400
V3.1: 5.5 MEDIUM
V2.0:(not available)
CVE-2023-49675

An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability.

Published: May 06, 2024; 8:15:07 AM -0400
V3.1: 7.8 HIGH
V2.0:(not available)
CVE-2023-6854

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Published: May 06, 2024; 7:15:46 AM -0400
V3.x:(not available)
V2.0:(not available)