Show filters
433 Total Results
Displaying 21-30 of 433
Sort by:
Attacker Value
Unknown
CVE-2024-33558
Disclosure Date: April 29, 2024 (last updated February 23, 2025)
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
0
Attacker Value
Unknown
CVE-2023-20959
Disclosure Date: March 24, 2023 (last updated February 23, 2025)
In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-249057848
0
Attacker Value
Unknown
CVE-2021-38698
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
0
Attacker Value
Unknown
CVE-2021-40378
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.
0
Attacker Value
Unknown
CVE-2021-40379
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.
0
Attacker Value
Unknown
CVE-2021-36232
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
0
Attacker Value
Unknown
CVE-2021-40088
Disclosure Date: August 25, 2021 (last updated February 23, 2025)
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.
0
Attacker Value
Unknown
CVE-2021-30874
Disclosure Date: August 24, 2021 (last updated February 23, 2025)
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.
0
Attacker Value
Unknown
CVE-2020-27466
Disclosure Date: August 20, 2021 (last updated February 23, 2025)
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.
0
Attacker Value
Unknown
CVE-2020-25359
Disclosure Date: August 20, 2021 (last updated February 23, 2025)
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.
0