Vulnerability index

Browse CVEs

63 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2023-6319EPSS 6% A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 … Webos No fix yet Fix from $1,9502024-04-09 HIGH 7.2 CVE-2023-6320 A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser… Webos No fix yet Fix from $1,9502024-04-09 CRITICAL 9.8 CVE-2023-6317 A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without … Webos No fix yet Fix from $2,3002024-04-09 HIGH 7.2 CVE-2023-6318 A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu… Webos No fix yet Fix from $1,9502024-04-09 CRITICAL 9.8 CVE-2024-2863EPSS 64% This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant. Lg Led Assistant Mitigation only Fix from $2,3002024-03-25 CRITICAL 9.8 CVE-2024-2862EPSS 51% This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant. Lg Led Assistant Mitigation only Fix from $2,3002024-03-25 CRITICAL 9.8 CVE-2024-1885 This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage. Webos Signage No fix yet Fix from $2,3002024-02-26 HIGH 8.8 CVE-2024-1886 This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage. Webos Signage Mitigation only Fix from $1,9502024-02-26 CRITICAL 9.8 CVE-2023-4614 This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to… Lg Led Assistant Mitigation only Fix from $2,3002023-09-04 HIGH 7.5 CVE-2023-4615 This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req… Lg Led Assistant Mitigation only Fix from $1,9502023-09-04 HIGH 7.5 CVE-2023-4616 This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not req… Lg Led Assistant Mitigation only Fix from $1,9502023-09-04 CRITICAL 9.8 CVE-2023-4613 This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to… Lg Led Assistant Mitigation only Fix from $2,3002023-09-04 HIGH 7.8 CVE-2022-45422 When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005. Smart Share No fix yet Fix from $1,9502022-11-21 CRITICAL 9.8 CVE-2022-23730 The public API error causes for the attacker to be able to bypass API access control. Webos No fix yet Fix from $2,3002022-03-11 HIGH 7.8 CVE-2022-23731 V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models. Webos No fix yet Fix from $1,9502022-03-11 HIGH 7.8 CVE-2022-23727 There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operat… Webos after 5.0 Fix from $1,9502022-01-28 CRITICAL 9.8 CVE-2021-38306EPSS 9% Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/pl… N1t1 Firmware No fix yet Fix from $2,3002021-08-24 MEDIUM 5.5 CVE-2020-7807 A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installati… Ipsfullhd Mitigation only Fix from $1,6002020-09-14 HIGH 7.8 CVE-2019-20781 An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur. Bridge 2019-04+ Fix from $1,9502020-04-29 HIGH 7.8 CVE-2019-20769 An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in… Pc Suite after 5.3.27 Fix from $1,9502020-04-17 HIGH 7.8 CVE-2020-9759 A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is… Webos No fix yet Fix from $1,9502020-03-23 CRITICAL 9.8 CVE-2018-14839 KEVEPSS 89% LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with p… N1a1 Firmware Mitigation only Fix from $2,3002019-05-14 HIGH 7.5 CVE-2019-7404 An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing… Gamp 7100 Firmware No fix yet Fix from $1,9502019-05-13 HIGH 7.0 CVE-2019-8372 The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to read and write arbitrary physi… Lha.sys 1.1.1811.2101+ Fix from $1,9502019-02-18 CRITICAL 9.8 CVE-2018-17173EPSS 56% LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. Supersign Cms No fix yet Fix from $2,3002018-09-21 CRITICAL 9.8 CVE-2018-16287EPSS 20% LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. Supersign Cms No fix yet Fix from $2,3002018-09-14 HIGH 8.6 CVE-2018-16288EPSS 36% LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. Supersign Cms No fix yet Fix from $1,9502018-09-14 HIGH 7.5 CVE-2018-16706EPSS 22% LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080. Supersign Cms No fix yet Fix from $1,9502018-09-14 CRITICAL 9.8 CVE-2018-16286EPSS 22% LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is lim… Supersign Cms No fix yet Fix from $2,3002018-09-14 HIGH 7.5 CVE-2018-16946EPSS 9% LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log &… Lnb5110 Firmware after 1508190 Fix from $1,9502018-09-12