In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local …
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local inform…
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privilege…
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access…
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), …
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller f…
The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, al…
The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definit…
The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check o…
The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' f…
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead …
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSaf…
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in bot…
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the ser…
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the aj…
Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the dev…
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users t…
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed …
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictio…
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.