CVE-2023-37214
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
Source: CVE-2023-37214
CVE-2023-37214
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
Source: CVE-2023-37214
CVE-2023-37213
Synel SYnergy Fingerprint Terminals – CWE-78: ‘OS Command Injection’
Source: CVE-2023-37213
CVE-2023-37215
JBL soundbar multibeam 5.1 – CWE-798: Use of Hard-coded Credentials
Source: CVE-2023-37215
CVE-2023-32227
Synel SYnergy Fingerprint Terminals – CWE-798: Use of Hard-coded Credentials
Source: CVE-2023-32227
CVE-2023-32226
Sysaid – CWE-552: Files or Directories Accessible to External Parties -Â
Authenticated users may exfiltrate files from the server via an unspecified method.
Source: CVE-2023-32226
CVE-2023-32225
Sysaid – CWE-434: Unrestricted Upload of File with Dangerous Type -Â
A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
Source: CVE-2023-32225
CVE-2023-36542
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The permission prevents unprivileged users from configuring Processors and Controller Services annotated with the new Reference Remote Resources restriction. Upgrading to Apache NiFi 1.23.0 is the recommended mitigation.
Source: CVE-2023-36542
CVE-2023-2313
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a malicious file. (Chromium security severity: High)
Source: CVE-2023-2313
CVE-2023-2314
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Source: CVE-2023-2314
CVE-2022-4922
Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Source: CVE-2022-4922