Show filters
2,806 Total Results
Displaying 321-330 of 2,806
Sort by:
Attacker Value
Unknown

CVE-2024-20805

Disclosure Date: January 04, 2024 (last updated February 25, 2025)
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
Attacker Value
Unknown

CVE-2024-20804

Disclosure Date: January 04, 2024 (last updated February 25, 2025)
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
Attacker Value
Unknown

CVE-2024-20803

Disclosure Date: January 04, 2024 (last updated February 25, 2025)
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
Attacker Value
Unknown

CVE-2024-20802

Disclosure Date: January 04, 2024 (last updated February 25, 2025)
Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.
Attacker Value
Unknown

CVE-2023-36381

Disclosure Date: December 28, 2023 (last updated February 25, 2025)
Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5.
Attacker Value
Unknown

CVE-2023-41796

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.
Attacker Value
Unknown

CVE-2023-48390

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and access the system to perform arbitrary system operations or disrupt service.
Attacker Value
Unknown

CVE-2023-48389

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Attacker Value
Unknown

CVE-2023-48388

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
Attacker Value
Unknown

CVE-2023-46348

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.