Show filters
433 Total Results
Displaying 21-30 of 433
Sort by:
Attacker Value
Unknown

CVE-2024-33558

Disclosure Date: April 29, 2024 (last updated February 23, 2025)
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
Attacker Value
Unknown

CVE-2023-20959

Disclosure Date: March 24, 2023 (last updated February 23, 2025)
In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-249057848
Attacker Value
Unknown

CVE-2021-38698

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
Attacker Value
Unknown

CVE-2021-40378

Disclosure Date: September 01, 2021 (last updated February 23, 2025)
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.
Attacker Value
Unknown

CVE-2021-40379

Disclosure Date: September 01, 2021 (last updated February 23, 2025)
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.
Attacker Value
Unknown

CVE-2021-36232

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
Attacker Value
Unknown

CVE-2021-40088

Disclosure Date: August 25, 2021 (last updated February 23, 2025)
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.
Attacker Value
Unknown

CVE-2021-30874

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.
Attacker Value
Unknown

CVE-2020-27466

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.
Attacker Value
Unknown

CVE-2020-25359

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.