Show filters
858 Total Results
Displaying 251-260 of 858
Sort by:
Attacker Value
Unknown
CVE-2023-34154
Disclosure Date: June 16, 2023 (last updated February 25, 2025)
Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources.
0
Attacker Value
Unknown
CVE-2023-34797
Disclosure Date: June 15, 2023 (last updated February 25, 2025)
Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information.
0
Attacker Value
Unknown
CVE-2023-34852
Disclosure Date: June 15, 2023 (last updated February 25, 2025)
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
0
Attacker Value
Unknown
CVE-2023-21142
Disclosure Date: June 15, 2023 (last updated February 25, 2025)
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262243665
0
Attacker Value
Unknown
CVE-2022-33163
Disclosure Date: June 15, 2023 (last updated February 25, 2025)
IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 228571.
0
Attacker Value
Unknown
CVE-2023-35147
Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2023-31142
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, if a site has modified their general category permissions, they could be set back to the default. This issue is patched in version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches. A workaround, only if you are modifying the general category permissions, is to use a new category for the same purpose.
0
Attacker Value
Unknown
CVE-2023-28603
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
0
Attacker Value
Unknown
CVE-2023-33695
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/io/FileUtil.java.
0
Attacker Value
Unknown
CVE-2023-31238
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.60), POWER METER SICAM Q100 (All versions < V2.60), POWER METER SICAM Q100 (All versions < V2.60), POWER METER SICAM Q100 (All versions < V2.60). Affected devices are missing cookie protection flags when using the default settings. An attacker who gains access to a session token can use it to impersonate a legitimate application user.
0