In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execu…
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execu…
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privile…
In music service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution pri…
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious applicat…
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for acc…
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…
There is an missing authorization issue in the system service. Since the component does not have permission check and permission protection,, resulti…
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…
There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of p…
In getInputMethodWindowVisibleHeight of InputMethodManagerService.java, there is a possible way to determine when another app is showing an IME due t…
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate thei…
The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticate…
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten…
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clie…
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due t…
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.
The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's set…
The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthent…
Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from pr…
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT cl…
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is…
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allow…
A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to conne…
A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-s…
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specifie…