Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2023-6319EPSS 6%
A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 …
Webos
No fix yet
HIGH 7.2
CVE-2023-6320
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser…
Webos
No fix yet
CRITICAL 9.8
CVE-2023-6317
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without …
Webos
No fix yet
HIGH 7.2
CVE-2023-6318
A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…
Webos
No fix yet
CRITICAL 9.8
CVE-2024-2863EPSS 64%
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
Lg Led Assistant
Mitigation only
CRITICAL 9.8
CVE-2024-2862EPSS 51%
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
Lg Led Assistant
Mitigation only
CRITICAL 9.8
CVE-2024-1885
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
Webos Signage
No fix yet
HIGH 8.8
CVE-2024-1886
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
Webos Signage
Mitigation only
CRITICAL 9.8
CVE-2023-4614
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…
Lg Led Assistant
Mitigation only
HIGH 7.5
CVE-2023-4615
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…
Lg Led Assistant
Mitigation only
HIGH 7.5
CVE-2023-4616
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req…
Lg Led Assistant
Mitigation only
CRITICAL 9.8
CVE-2023-4613
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to…
Lg Led Assistant
Mitigation only
HIGH 7.8
CVE-2022-45422
When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.
Smart Share
No fix yet
CRITICAL 9.8
CVE-2022-23730
The public API error causes for the attacker to be able to bypass API access control.
Webos
No fix yet
HIGH 7.8
CVE-2022-23731
V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
Webos
No fix yet
HIGH 7.8
CVE-2022-23727
There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operat…
Webos
after 5.0
CRITICAL 9.8
CVE-2021-38306EPSS 9%
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/pl…
N1t1 Firmware
No fix yet
MEDIUM 5.5
CVE-2020-7807
A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installati…
Ipsfullhd
Mitigation only
HIGH 7.8
CVE-2019-20781
An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.
Bridge
2019-04+
HIGH 7.8
CVE-2019-20769
An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in…
Pc Suite
after 5.3.27
HIGH 7.8
CVE-2020-9759
A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is…
Webos
No fix yet
CRITICAL 9.8
CVE-2018-14839 KEVEPSS 89%
LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with p…
N1a1 Firmware
Mitigation only
HIGH 7.5
CVE-2019-7404
An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing…
Gamp 7100 Firmware
No fix yet
HIGH 7.0
CVE-2019-8372
The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physi…
Lha.sys
1.1.1811.2101+
CRITICAL 9.8
CVE-2018-17173EPSS 56%
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
Supersign Cms
No fix yet
CRITICAL 9.8
CVE-2018-16287EPSS 20%
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
Supersign Cms
No fix yet
HIGH 8.6
CVE-2018-16288EPSS 36%
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
Supersign Cms
No fix yet
HIGH 7.5
CVE-2018-16706EPSS 22%
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
Supersign Cms
No fix yet
CRITICAL 9.8
CVE-2018-16286EPSS 22%
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is lim…
Supersign Cms
No fix yet
HIGH 7.5
CVE-2018-16946EPSS 9%
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log &…
Lnb5110 Firmware
after 1508190