| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| An attacker can export other users' plant information. |
| An unauthenticated attacker can hijack other users' devices and potentially control them. |
| Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). |
| Unauthenticated attackers can rename "rooms" of arbitrary users. |
| An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs. |
| An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID. |
| Unauthenticated attackers can query an API endpoint and get device details. |
| An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API. |
| Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts. |
| Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account. |
| Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. |
| The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts |
| Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms"). |
| An attacker can change registered email addresses of other users and take over arbitrary accounts. |
| An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username. |
| Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes"). |
| Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to view the shipment addresses of different virtual instance via the _com_liferay_commerce_order_web_internal_portlet_CommerceOrderPortlet_commerceOrderId parameter. |
| An unauthenticated attacker can obtain EV charger energy consumption information of other users. |
| An unauthenticated attacker can obtain other users' charger information. |
| An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms"). |