Vulnerabilities (CVE)

Filtered by CWE-862
Total 2747 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-48417 1 Google 2 Chromecast, Chromecast Firmware 2023-12-13 N/A 9.8 CRITICAL
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
CVE-2023-5710 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information such as database credentials.
CVE-2023-5711 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information provided by PHP info.
CVE-2023-5712 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive global value information.
CVE-2023-5713 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.
CVE-2023-5714 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve data key specs.
CVE-2023-44113 1 Huawei 2 Emui, Harmonyos 2023-12-11 N/A 7.5 HIGH
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-46354 1 Myprestamodules 1 Orders \(csv\, Excel\) Export Pro 2023-12-09 N/A 7.5 HIGH
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer/ps_address tables such as name / surname / email / phone number / full postal address.
CVE-2023-42749 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42748 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42747 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42746 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42745 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42744 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-42743 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42710 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42742 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-42741 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42740 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42739 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed