In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check.…
In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local inf…
In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no…
In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation …
In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of pr…
In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclo…
In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user …
In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure wit…
The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid…
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_d…
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_c…
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all…
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in …
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem…
The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the…
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment…
The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteReq…
The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions…
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi…
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in…
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe…
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plug…
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. …
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in versions up to, and including,…
An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai_ajax function. This…
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalat…
Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device passwo…
Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authenticatio…
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agen…