Search Results (10392 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-30730 1 Samsung 1 Samsung Pass 2024-11-21 4.6 Medium
Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.
CVE-2022-30727 1 Google 1 Android 2024-11-21 6.2 Medium
Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.
CVE-2022-30725 1 Google 1 Android 2024-11-21 4 Medium
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVE-2022-30724 1 Google 1 Android 2024-11-21 4 Medium
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVE-2022-30723 1 Google 1 Android 2024-11-21 4 Medium
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
CVE-2022-30722 1 Google 1 Android 2024-11-21 6.2 Medium
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.
CVE-2022-30717 1 Google 1 Android 2024-11-21 4 Medium
Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.
CVE-2022-30716 1 Google 1 Android 2024-11-21 4 Medium
Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.
CVE-2022-30715 1 Google 1 Android 2024-11-21 4 Medium
Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.
CVE-2022-30670 2 Adobe, Microsoft 2 Robohelp Server, Windows 2024-11-21 8.8 High
RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploitation of this issue does not require user interaction.
CVE-2022-30624 1 Chcnav 2 P5e Gnss, P5e Gnss Firmware 2024-11-21 6.8 Medium
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.
CVE-2022-30623 1 Chcnav 2 P5e Gnss, P5e Gnss Firmware 2024-11-21 5.9 Medium
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.
CVE-2022-30270 1 Motorola 2 Ace1000, Ace1000 Firmware 2024-11-21 9.8 Critical
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts (root, abuilder, acelogin, cappl, ace), all of which come with default credentials. Although the ACE1000 documentation mentions the root, abuilder and acelogin accounts and instructs users to change the default credentials, the cappl and ace accounts remain undocumented and thus are unlikely to have their credentials changed.
CVE-2022-30238 1 Schneider-electric 4 Wiser Smart Eer21000, Wiser Smart Eer21000 Firmware, Wiser Smart Eer21001 and 1 more 2024-11-21 8.3 High
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
CVE-2022-30034 1 Flower Project 1 Flower 2024-11-21 8.6 High
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny service by shutting down Celery task nodes.
CVE-2022-2901 1 Chatwoot 1 Chatwoot 2024-11-21 7.1 High
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
CVE-2022-2787 1 Debian 2 Debian Linux, Schroot 2024-11-21 4.3 Medium
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
CVE-2022-2675 1 Unitree 2 Go 1, Go 1 Firmware 2024-11-21 6.5 Medium
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.
CVE-2022-2631 1 Tooljet 1 Tooljet 2024-11-21 8.8 High
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
CVE-2022-2595 1 Kromit 1 Titra 2024-11-21 10.0 Critical
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.