5.3

CVSS3.1

CVE-2023-41927 - Weak TLS Cipher Suites Supported in Kiloview P1/P2 devices

The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing the risk of cryptographic weaknesses.

πŸ“… Published: July 2, 2024, 7:43 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2023-41926 - Insufficiently protected credentials in Kiloview P1/P2 devices

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.

πŸ“… Published: July 2, 2024, 7:43 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2023-41923 - Weak Password Requirements in Kiloview P1/P2 devices

The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.

πŸ“… Published: July 2, 2024, 7:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2023-41922 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Kiloview P1…

A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur. Multiple areas within the administration interface of the webserver lack adequate input validation…

πŸ“… Published: July 2, 2024, 7:42 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:21 a.m.

9.8

CVSS3.1

CVE-2023-41921 - Download of Code Without Integrity Check in Kiloview P1/P2 devices

A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and integrity of the code. This vulnerability can allow attackers to modify the firmware before uploading it to the system, thus achieving …

πŸ“… Published: July 2, 2024, 7:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2023-41920 - Authentication Bypass by Primary Weakness in Kiloview P1/P2 devices

The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.

πŸ“… Published: July 2, 2024, 7:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2023-41919 - Use of Hard-coded Credentials in Kiloview P1/P2 devices

Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.

πŸ“… Published: July 2, 2024, 7:42 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:21 a.m.

10

CVSS3.1

CVE-2023-41918 - Missing Authentication for Critical Function in Kiloview P1/P2 devices

A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, access to privileged functions, or even the execution of arbitrary code.

πŸ“… Published: July 2, 2024, 7:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2023-41917 - Improper input validation in Kiloview P1/P2 devices allows for remote code execution

Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement feature, enabling unauthorized code execution.

πŸ“… Published: July 2, 2024, 7:41 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2024-37479 - WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.8.1 - Contributor+ Local File Inclusion…

Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.8.1.

πŸ“… Published: July 2, 2024, 7:40 a.m. πŸ”„ Last Modified: July 10, 2025, 10:41 p.m.
Total resulsts: 347742
Page 9138 of 34,775
Β« previous page Β» next page
Filters