Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12.1 allows…
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege …
In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing permission check. This could lea…
In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disc…
In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to loc…
In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could lead to local …
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to loca…
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to …
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lea…
In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to lo…
A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate cr…
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with O…
Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permissi…
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering…
The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_aj…
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b…
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an …
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-…
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMet…
In sendMessage of OneToOneChatImpl.java (? TBD), there is a possible way to send an RCS message without permissions due to a missing permission check…
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This coul…
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missi…
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerat…
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect …
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to …
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application…
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to …
SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthor…