Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Angry Yack Logo
Total 34640 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38370 1 Glpi-project 1 Glpi 2025-02-10 N/A 5.3 MEDIUM
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
CVE-2023-27703 1 Mypikpak 1 Pikpak 2025-02-10 N/A 3.3 LOW
The Android version of pikpak v1.29.2 was discovered to contain an information leak via the debug interface.
CVE-2023-27654 1 Whoapp 1 Who 2025-02-10 N/A 9.8 CRITICAL
An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.
CVE-2023-27653 1 Whoapp 1 Who 2025-02-10 N/A 7.5 HIGH
An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a denial of service via the SharedPreference files.
CVE-2023-27651 1 Egostudiogroup 1 Superclean 2025-02-10 N/A 7.8 HIGH
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the _default_.xml file.
CVE-2023-27647 1 Dualspace 1 Lock Master 2025-02-10 N/A 7.1 HIGH
An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method.
CVE-2023-23591 1 Terminalfour 1 Terminalfour 2025-02-10 N/A 4.9 MEDIUM
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
CVE-2018-15472 1 Gitlab 1 Gitlab 2025-02-10 N/A 7.5 HIGH
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq jobs without any timeout.
CVE-2024-6411 1 Metagauss 1 Profilegrid 2025-02-10 N/A 8.8 HIGH
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their user capabilities to Administrator.
CVE-2024-37484 1 Zephyr-one 1 Zephyr Project Manager 2025-02-10 N/A 8.8 HIGH
Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
CVE-2025-0802 1 Mayurik 1 Best Employee Management System 2025-02-10 7.5 HIGH 7.3 HIGH
A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-29580 1 Yasm Project 1 Yasm 2025-02-08 N/A 5.5 MEDIUM
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.
CVE-2023-29574 1 Axiosys 1 Bento4 2025-02-08 N/A 5.5 MEDIUM
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
CVE-2023-29571 1 Cesanta 1 Mjs 2025-02-08 N/A 5.5 MEDIUM
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial of Service (DoS).
CVE-2022-45180 1 Liveboxcloud 1 Vdesk 2025-02-07 N/A 6.5 MEDIUM
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).
CVE-2025-21185 1 Microsoft 1 Edge Chromium 2025-02-07 N/A 6.5 MEDIUM
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-45178 1 Liveboxcloud 1 Vdesk 2025-02-07 N/A 8.8 HIGH
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already logged in as a SAML User) is able to achieve privilege escalation from a low-privilege user (FGM user) to an administrative user (GGU user), including the administrator, or create n ...

Show More

CVE-2024-20864 1 Samsung 1 Android 2025-02-07 N/A 5.5 MEDIUM
Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.
CVE-2024-20855 1 Samsung 1 Android 2025-02-07 N/A 2.4 LOW
Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.
CVE-2024-39557 1 Juniper 1 Junos Os Evolved 2025-02-07 N/A 6.5 MEDIUM
An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a memory leak, eventually exhausting all system memory, leading to a system crash and Denial of Service (DoS). Certain MAC table updates cause a small amount of memory to leak.  Once memory utilization reaches its limit, the issue will result in a system crash and restart. To identify the issue, execute ...

Show More

CVE-2024-5868 1 Wpwebelite 1 Woocommerce Social Login 2025-02-07 N/A 6.5 MEDIUM
The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
CVE-2024-39513 1 Juniper 1 Junos Os Evolved 2025-02-07 N/A 5.5 MEDIUM
An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a Denial of Service (DoS). When a specific "clear" command is run, the Advanced Forwarding Toolkit manager (evo-aftmand-bt or evo-aftmand-zx) crashes and restarts. The crash impacts all traffic going through the FPCs, causing a DoS. Running the command repeatedly leads to a sustained DoS condition. This issue affects Junos OS Evo ...

Show More

CVE-2024-0631 1 Duitku 1 Duitku Payment Gateway 2025-02-07 N/A 5.3 MEDIUM
The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.4. This makes it possible for unauthenticated attackers to change the payment status of orders to failed.
CVE-2024-39511 1 Juniper 1 Junos 2025-02-07 N/A 5.5 MEDIUM
An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the CLI to cause a Denial of Service (DoS). On running a specific operational dot1x command, the dot1x daemon crashes. An attacker can cause a sustained DoS condition by running this command repeatedly. When the crash occurs, the authentication status of any 802.1x clients is cleared, and any authorized dot1x port becomes una ...

Show More

CVE-2024-2088 1 Nextscripts 1 Social Networks Auto Poster 2025-02-07 N/A 8.5 HIGH
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and secrets.
CVE-2024-1136 1 Wpshopmart 1 Coming Soon Page \& Maintenance Mode 2025-02-07 N/A 5.3 MEDIUM
The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to view a site with maintenance mode or coming-soon mode enabled to view the site's content.
CVE-2024-20847 1 Samsung 1 Android 2025-02-07 N/A 4.0 MEDIUM
Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.
CVE-2023-30636 1 Tikv 1 Tikv 2025-02-07 N/A 7.5 HIGH
TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader") upon an attempt to start a node in a situation where the context deadline is exceeded
CVE-2023-30635 1 Tikv 1 Tikv 2025-02-07 N/A 7.5 HIGH
TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from the Placement Driver.
CVE-2023-30524 1 Jenkins 1 Report Portal 2025-02-07 N/A 4.3 MEDIUM
Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.
CVE-2023-20866 1 Vmware 1 Spring Session 2025-02-07 N/A 6.5 MEDIUM
In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application is vulnerable if it is using HeaderHttpSessionIdResolver.
CVE-2023-27193 1 Dualspace 1 Space Clean \& Super Cleaner 2025-02-07 N/A 7.8 HIGH
An issue found in DUALSPACE v.1.1.3 allows a local attacker to gain privileges via the key_ad_new_user_avoid_time field.
CVE-2025-21325 1 Microsoft 6 Windows 10 21h2, Windows 10 22h2, Windows 11 22h2 and 3 more 2025-02-07 N/A 7.8 HIGH
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2024-1591 1 Beyondtrust 1 Privilege Management For Windows 2025-02-07 N/A 3.3 LOW
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy. This allows them to view the policy and potentially find configuration issues.
CVE-2024-3270 1 Thingsboard 1 Thingsboard 2025-02-07 4.7 MEDIUM 3.8 LOW
A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259282 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure and replied to be planning to fix this issue in version 3.7.
CVE-2024-32100 1 Sandhillsdev 1 Easy Digital Downloads 2025-02-07 N/A 5.3 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
CVE-2023-6922 1 Acurax 1 Under Construction \/ Maintenance Mode 2025-02-07 N/A 4.3 MEDIUM
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_subscribe_ajax' function. This can allow authenticated attackers to extract sensitive data such as names and email addresses of subscribed visitors.
CVE-2024-0680 1 Wpexpertdeveloper 1 Wp Private Content Plus 2025-02-07 N/A 5.3 MEDIUM
The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
CVE-2024-0682 1 Theandystratton 1 Pagerestrict 2025-02-07 N/A 5.3 MEDIUM
The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
CVE-2024-0975 1 Brandonwamboldt 1 Wordpress Access Control 2025-02-07 N/A 5.3 MEDIUM
The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Make Website Members Only" feature (when unset) and view restricted page and post content.