Search Results (375438 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-40643 2 Google, Unisoc 2 Android, Sc9863a 2024-11-21 5.5 Medium
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-40642 2 Google, Unisoc 2 Android, Sc9863a 2024-11-21 5.5 Medium
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-40641 2 Google, Unisoc 2 Android, Sc9863a 2024-11-21 5.5 Medium
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-40640 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-11-21 5.5 Medium
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVE-2023-40639 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-11-21 5.5 Medium
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVE-2023-40638 2 Google, Unisoc 5 Android, S8000, T760 and 2 more 2024-11-21 4.4 Medium
In Telecom service, there is a possible missing permission check. This could lead to local denial of service with System execution privileges needed
CVE-2023-40637 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-11-21 5.5 Medium
In telecom service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
CVE-2023-40636 2 Google, Unisoc 5 Android, S8000, T760 and 2 more 2024-11-21 4.4 Medium
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with System execution privileges needed
CVE-2023-40635 2 Google, Unisoc 11 Android, S8000, Sc9863a and 8 more 2024-11-21 7.8 High
In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-40634 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-11-21 7.8 High
In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-40633 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-11-21 5.5 Medium
In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-40632 2 Google, Unisoc 4 Android, T606, T612 and 1 more 2024-11-21 7.5 High
In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure no additional execution privileges needed
CVE-2023-40631 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-11-21 4.4 Medium
In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
CVE-2023-40630 1 Joomcode 1 Jcdashboard 2024-11-21 9.8 Critical
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
CVE-2023-40629 1 King-products 1 Lms King Lite 2024-11-21 9.8 Critical
SQLi vulnerability in LMS Lite component for Joomla.
CVE-2023-40628 1 Extplorer 1 Extplorer 2024-11-21 6.1 Medium
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
CVE-2023-40627 1 Mlwebtechnologies 1 Livingword 2024-11-21 6.1 Medium
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
CVE-2023-40625 1 Sap 1 S4core 2024-11-21 5.4 Medium
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system.
CVE-2023-40624 1 Sap 1 Netweaver Application Server Abap 2024-11-21 5.5 Medium
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could thereby control the behavior of this web-application.
CVE-2023-40623 1 Sap 1 Businessobjects 2024-11-21 6.2 Medium
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.