HackAndPwn
Security & Vulnerability Researcher / Professional Penetration Tester

Home

  • CVE-2023-29152

    PTC Vuforia Studio before 9.9 contains an improper authorization vulnerability caused by insufficient validation of filename parameters in requests. An attacker could delete any file accessible under the permissions of the Vuforia server account.


  • CVE-2023-27881

    PTC Vuforia Studio before 9.9 contains an unrestricted upload of file with dangerous type vulnerability. A user could use the Upload Resource functionality to upload files to any location on disk.


  • CVE-2023-24476

    PTC Vuforia Studio before 9.9 contains an improper authorization vulnerability. An attacker with local access to the machine could record traffic and resend requests without the server authenticating that the user or session are valid.


  • CVE-2023-29080

    Dell Command Integration Suite, Dell Command Configure, and Dell Command Intel vPro Out of Band contain an InstallShield improper access control vulnerability that could be exploited by malicious users to compromise the affected system.

  • CVE-2023-28051

    Dell Power Manager versions 3.10 and prior contain an improper access control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.



     Page: 7 of 21     
buy me a coffee