Show filters
526 Total Results
Displaying 311-320 of 526
Sort by:
Attacker Value
Unknown
CVE-2022-39879
Disclosure Date: November 09, 2022 (last updated February 24, 2025)
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
0
Attacker Value
Unknown
CVE-2022-39890
Disclosure Date: November 09, 2022 (last updated February 24, 2025)
Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
0
Attacker Value
Unknown
CVE-2022-39356
Disclosure Date: November 02, 2022 (last updated February 24, 2025)
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version. A workaround is temporarily disabling invitations with `SiteSetting.max_invites_per_day = 0` or scope them to individual email addresses.
0
Attacker Value
Unknown
CVE-2022-27583
Disclosure Date: October 31, 2022 (last updated February 24, 2025)
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.
0
Attacker Value
Unknown
CVE-2022-39329
Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2022-39342
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users whose model has a relation defined as a tupleset (the right hand side of a ‘from’ statement) that involves anything other than a direct relationship (e.g. ‘as self’) are vulnerable. Version 0.2.4 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2022-39341
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) defined on tupleset relations in their authorization model are vulnerable. Version 0.2.4 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2022-39340
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2022-39322
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their field-level access control not being used. List-level access control is not affected. Field-level access control for fields other than `multiselect` are not affected. Version 2.3.1 contains a fix for this issue. As a workaround, stop using the `multiselect` field.
0
Attacker Value
Unknown
CVE-2022-39873
Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.
0