Show filters
425 Total Results
Displaying 341-350 of 425
Sort by:
Attacker Value
Unknown

CVE-2021-43512

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys.
Attacker Value
Unknown

CVE-2022-1044

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
Attacker Value
Unknown

CVE-2021-25266

Disclosure Date: April 27, 2022 (last updated February 23, 2025)
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
Attacker Value
Unknown

CVE-2022-1257

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.
Attacker Value
Unknown

CVE-2021-27456

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.
Attacker Value
Unknown

CVE-2018-25031

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
Attacker Value
Unknown

CVE-2022-24929

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
Attacker Value
Unknown

CVE-2022-0881

Disclosure Date: March 09, 2022 (last updated February 23, 2025)
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.
Attacker Value
Unknown

CVE-2021-3716

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2022-25264

Disclosure Date: February 25, 2022 (last updated February 23, 2025)
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.