Show filters
424 Total Results
Displaying 311-320 of 424
Sort by:
Attacker Value
Unknown

CVE-2023-0580

Disclosure Date: April 06, 2023 (last updated February 24, 2025)
Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My Control System (on-premise) application, the following ones are affected by this vulnerability: User Interface System Monitoring1 Asset Inventory This issue affects My Control System (on-premise): from 5.0;0 through 5.13.
Attacker Value
Unknown

CVE-2023-20962

Disclosure Date: March 24, 2023 (last updated February 26, 2025)
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-256590210
Attacker Value
Unknown

CVE-2022-2837

Disclosure Date: March 03, 2023 (last updated February 24, 2025)
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
Attacker Value
Unknown

CVE-2022-2835

Disclosure Date: March 03, 2023 (last updated February 24, 2025)
A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of <service>.<namespace>.svc.
Attacker Value
Unknown

CVE-2022-38090

Disclosure Date: February 16, 2023 (last updated February 24, 2025)
Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2022-4903

Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 7.0.71 is able to address this issue. The patch is identified as dad49c9ef26a598619fc48d2697151a02987d478. It is recommended to upgrade the affected component. VDB-220470 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-39043

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts.
Attacker Value
Unknown

CVE-2021-36546

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.
Attacker Value
Unknown

CVE-2022-2815

Disclosure Date: January 14, 2023 (last updated February 24, 2025)
Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
Attacker Value
Unknown

CVE-2023-22469

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. When getting the reference preview for Deck cards the user has no access to, unauthorized user could eventually get the cached data of a user that has access. There are currently no known workarounds. It is recommended that the Nextcloud app Deck is upgraded to 1.8.2.