Vulnerability index

Browse CVEs

54 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Webos HIGH 7.2
CVE-2023-6318

A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…

No fix yet
Fix from $1,950 2024-04-09
Lg Led Assistant CRITICAL 9.8
CVE-2024-2863EPSS 64%

This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

Mitigation only
Fix from $2,300 2024-03-25
Lg Led Assistant CRITICAL 9.8
CVE-2024-2862EPSS 51%

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

Mitigation only
Fix from $2,300 2024-03-25
Webos Signage CRITICAL 9.8
CVE-2024-1885

This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

No fix yet
Fix from $2,300 2024-02-26
Webos Signage HIGH 8.8
CVE-2024-1886

This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

Mitigation only
Fix from $1,950 2024-02-26
Lg Led Assistant CRITICAL 9.8
CVE-2023-4614

This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…

Mitigation only
Fix from $2,300 2023-09-04
Lg Led Assistant HIGH 7.5
CVE-2023-4615

This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…

Mitigation only
Fix from $1,950 2023-09-04
Lg Led Assistant HIGH 7.5
CVE-2023-4616

This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…

Mitigation only
Fix from $1,950 2023-09-04
Lg Led Assistant CRITICAL 9.8
CVE-2023-4613

This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…

Mitigation only
Fix from $2,300 2023-09-04
Smart Share HIGH 7.8
CVE-2022-45422

When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.

No fix yet
Fix from $1,950 2022-11-21
Webos CRITICAL 9.8
CVE-2022-23730

The public API error causes for the attacker to be able to bypass API access control.

No fix yet
Fix from $2,300 2022-03-11
Webos HIGH 7.8
CVE-2022-23731

V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.

No fix yet
Fix from $1,950 2022-03-11
N1t1 Firmware CRITICAL 9.8
CVE-2021-38306EPSS 9%

Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/pl…

No fix yet
Fix from $2,300 2021-08-24
Ipsfullhd MEDIUM 5.5
CVE-2020-7807

A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installati…

Mitigation only
Fix from $1,600 2020-09-14
Webos HIGH 7.8
CVE-2020-9759

A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is…

No fix yet
Fix from $1,950 2020-03-23
N1a1 Firmware CRITICAL 9.8
CVE-2018-14839 KEVEPSS 89%

LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with p…

Mitigation only
Fix from $2,300 2019-05-14
Gamp 7100 Firmware HIGH 7.5
CVE-2019-7404

An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing…

No fix yet
Fix from $1,950 2019-05-13
Supersign Cms CRITICAL 9.8
CVE-2018-17173EPSS 56%

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

No fix yet
Fix from $2,300 2018-09-21
Supersign Cms CRITICAL 9.8
CVE-2018-16287EPSS 20%

LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.

No fix yet
Fix from $2,300 2018-09-14
Supersign Cms HIGH 8.6
CVE-2018-16288EPSS 36%

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

No fix yet
Fix from $1,950 2018-09-14
Supersign Cms HIGH 7.5
CVE-2018-16706EPSS 22%

LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

No fix yet
Fix from $1,950 2018-09-14
Supersign Cms CRITICAL 9.8
CVE-2018-16286EPSS 22%

LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is lim…

No fix yet
Fix from $2,300 2018-09-14
Lg Mobile MEDIUM 5.5
CVE-2016-10135

An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5…

Mitigation only
Fix from $1,600 2017-01-13
L 04d MEDIUM 5.0
CVE-2014-7243

LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers…

Mitigation only
Fix from $1,600 2014-12-05