Show filters
609 Total Results
Displaying 61-70 of 609
Sort by:
Attacker Value
Unknown

CVE-2021-3456

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.
Attacker Value
Unknown

CVE-2021-39790

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-186405146
Attacker Value
Unknown

CVE-2021-39789

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203880906
Attacker Value
Unknown

CVE-2020-35501

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
Attacker Value
Unknown

CVE-2022-1177

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
Attacker Value
Unknown

CVE-2020-24771

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
Attacker Value
Unknown

CVE-2021-28505

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.
Attacker Value
Unknown

CVE-2021-39876

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.
Attacker Value
Unknown

CVE-2022-0720

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.
Attacker Value
Unknown

CVE-2022-24783

Disclosure Date: March 25, 2022 (last updated February 23, 2025)
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This vulnerability does not affect users of Deno Deploy. The vulnerability has been patched in Deno 1.20.3. There is no workaround. All users are recommended to upgrade to 1.20.3 immediately.