Show filters
874 Total Results
Displaying 81-90 of 874
Sort by:
Attacker Value
Unknown
CVE-2022-20352
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-222473855
0
Attacker Value
Unknown
CVE-2022-20349
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315522
0
Attacker Value
Unknown
CVE-2022-20348
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529
0
Attacker Value
Unknown
CVE-2022-2732
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
0
Attacker Value
Unknown
CVE-2022-1323
Disclosure Date: August 08, 2022 (last updated February 24, 2025)
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.
0
Attacker Value
Unknown
CVE-2022-2459
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for email invited members to join a project even after the Group Owner has enabled the setting to prevent members from being added to projects in a group, if the invite was sent before the setting was enabled.
0
Attacker Value
Unknown
CVE-2022-36836
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.
0
Attacker Value
Unknown
CVE-2022-31128
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly verify permissions when creating branches with the REST API in Git repositories using the fine grained permissions. Users can create branches via the REST endpoint `POST git/:id/branches` regardless of the permissions set on the repository. This issue has been fixed in version 13.10.99.82 Tuleap Community Edition as well as in version 13.10-3 of Tuleap Enterprise Edition. Users are advised to upgrade. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-26429
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07025415; Issue ID: ALPS07025415.
0
Attacker Value
Unknown
CVE-2022-2369
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
0