Total
401 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-22894 | 2 Alpha-innotec, Novelan | 4 Heat Pumps, Heat Pumps Firmware, Heat Pumps and 1 more | 2024-11-21 | N/A | 6.8 MEDIUM |
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file. | |||||
CVE-2024-20692 | 1 Microsoft | 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more | 2024-11-21 | N/A | 5.7 MEDIUM |
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | |||||
CVE-2023-7237 | 1 Lantronix | 2 Xport Edge, Xport Edge Firmware | 2024-11-21 | N/A | 5.7 MEDIUM |
Lantronix XPort sends weakly encoded credentials within web request headers. | |||||
CVE-2023-4333 | 2 Broadcom, Microsoft | 2 Raid Controller Web Interface, Windows | 2024-11-21 | N/A | 5.5 MEDIUM |
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server | |||||
CVE-2023-4129 | 1 Dell | 1 Data Protection Central | 2024-11-21 | N/A | 5.9 MEDIUM |
Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext. | |||||
CVE-2023-48051 | 1 Carglglz | 1 Upydev | 2024-11-21 | N/A | 7.5 HIGH |
An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding. | |||||
CVE-2023-48034 | 1 Acer | 2 Sk-9662, Sk-9662 Firmware | 2024-11-21 | N/A | 6.1 MEDIUM |
An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption. | |||||
CVE-2023-47373 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-47372 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-47370 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-47369 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications. | |||||
CVE-2023-47368 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-47367 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-47366 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-47365 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-47364 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims | |||||
CVE-2023-47363 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | |||||
CVE-2023-46894 | 1 Espressif | 1 Esptool | 2024-11-21 | N/A | 7.5 HIGH |
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm. | |||||
CVE-2023-44690 | 1 Dbcli | 1 Mycli | 2024-11-21 | N/A | 7.5 HIGH |
Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py | |||||
CVE-2023-43776 | 1 Eaton | 44 Easy-box-e4-ac1, Easy-box-e4-ac1 Firmware, Easy-box-e4-dc1 and 41 more | 2024-11-21 | N/A | 6.8 MEDIUM |
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending). |