Search Results (8327 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-20125 1 Cisco 1 Identity Services Engine 2025-03-28 9.1 Critical
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
CVE-2022-4872 1 Chained Products Project 1 Chained Products 2025-03-27 4.3 Medium
The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'
CVE-2023-6821 1 Bestwebsoft 1 Error Log Viewer 2025-03-27 6.5 Medium
The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization
CVE-2022-47450 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVE-2022-47333 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVE-2022-47332 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVE-2022-47330 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVE-2022-44421 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In wlan driver, there is a possible missing permission check. This could lead to local In wlan driver, information disclosure.
CVE-2021-36225 1 Westerndigital 2 My Cloud Os, My Cloud Pr4100 2025-03-26 8.8 High
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
CVE-2023-25014 1 In2code 1 Femanager 2025-03-26 8.6 High
An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.
CVE-2022-42909 1 Wepanow 1 Print Away 2025-03-26 6.5 Medium
WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for documents they don“t own and print hem without authorization. In order to exploit this vulnerability, the user must have an account with wepanow.com or any of the institutions they serve, and be logged in.
CVE-2022-47367 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 4.8 Medium
In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
CVE-2022-47325 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 6.4 Medium
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVE-2022-47324 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 6.4 Medium
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVE-2023-0678 1 Phpipam 1 Phpipam 2025-03-26 5.3 Medium
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
CVE-2022-47361 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 7.8 High
In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVE-2022-47360 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVE-2022-47359 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVE-2022-47358 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In log service, there is a missing permission check. This could lead to local denial of service in log service.
CVE-2022-47357 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-26 5.5 Medium
In log service, there is a missing permission check. This could lead to local denial of service in log service.