Export limit exceeded: 351558 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (7908 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-33970 1 Kanboard 1 Kanboard 2025-01-08 5.4 Medium
Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a `missing access control` was found, which allows a User with the lowest privileges to leak all the tasks and projects titles within the software, even if they are not invited or it's a personal project. This could also lead to private/critical information being leaked if such information is in the title. This issue has been addressed in version 1.2.30. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-30915 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-08 5.5 Medium
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVE-2023-30914 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-08 5.5 Medium
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVE-2023-30866 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-08 5.5 Medium
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVE-2023-30865 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-08 5.5 Medium
In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVE-2023-30864 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-08 7.8 High
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVE-2022-48445 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-07 5.9 Medium
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVE-2022-48444 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-07 5.9 Medium
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVE-2022-48443 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-07 5.9 Medium
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVE-2022-48442 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-07 6.2 Medium
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVE-2022-48441 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-07 6.2 Medium
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVE-2022-48440 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-07 6.2 Medium
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
CVE-2022-48390 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-07 7.3 High
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
CVE-2023-30948 1 Palantir 1 Foundry Comments 2025-01-07 6.5 Medium
A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content. This defect was fixed in Foundry Comments 2.249.0, and a patch was rolled out to affected Foundry environments. No further intervention is required at this time.
CVE-2023-3230 1 Fossbilling 1 Fossbilling 2025-01-02 7.5 High
Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.
CVE-2024-56349 1 Jetbrains 1 Teamcity 2025-01-02 5.3 Medium
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
CVE-2023-45246 4 Acronis, Apple, Linux and 1 more 5 Agent, Cyber Protect Cloud Agent, Macos and 2 more 2025-01-02 7.1 High
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36343, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.
CVE-2023-35149 1 Jenkins 1 Digital.ai App Management Publisher 2024-12-30 6.5 Medium
A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
CVE-2021-4362 1 Wpkube 1 Kiwi Social Share 2024-12-28 9.8 Critical
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated attackers to read and modify arbitrary options on a WordPress site that can be used for complete site takeover. This was a previously fixed vulnerability that was reintroduced in this version.
CVE-2023-36504 1 Bbsetheme 1 Bbs E-popup 2024-12-26 6.5 Medium
Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.