Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2023-21141

Description: In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262244249

EPSS Score: 0.04%

Source: CVE
December 18th, 2024 (6 months ago)

CVE-2023-21139

Description: In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-271845008

EPSS Score: 0.04%

Source: CVE
December 18th, 2024 (6 months ago)

CVE-2023-21138

Description: In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-273260090

EPSS Score: 0.04%

Source: CVE
December 18th, 2024 (6 months ago)

CVE-2024-5660

Description: Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection.

EPSS Score: 0.04%

Source: CVE
December 17th, 2024 (6 months ago)

CVE-2024-56112

Description: CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.

EPSS Score: 0.04%

Source: CVE
December 17th, 2024 (6 months ago)

CVE-2024-56087

Description: An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

EPSS Score: 0.04%

Source: CVE
December 17th, 2024 (6 months ago)

CVE-2024-56086

Description: An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.

EPSS Score: 0.04%

Source: CVE
December 17th, 2024 (6 months ago)

CVE-2024-56085

Description: An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

EPSS Score: 0.04%

Source: CVE
December 17th, 2024 (6 months ago)

CVE-2024-56084

Description: An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.

EPSS Score: 0.04%

Source: CVE
December 17th, 2024 (6 months ago)

CVE-2024-56083

Description: Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin session to social media, or publicly streams their Devin session.

EPSS Score: 0.05%

Source: CVE
December 17th, 2024 (6 months ago)