6.5
CVE-2024-42191 - HCL Traveler for Microsoft Outlook (HTMO) is susceptible to COM hijacking
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
6.5
CVE-2024-42190 - HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
6.8
CVE-2024-23589 - HCL Glovius Cloud is susceptible to an Outdated Hash Algorithm vulnerability
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs
8.3
CVE-2024-13917 - Intent Injection in Kruger&Matz AppLock application
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permis…
6.9
CVE-2024-13916 - Exposure of Applications' Encryption PINs in Kruger&Matz AppLock
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider's public method query() allows…
6.9
CVE-2024-13915 - Unrestricted Access to Exported Service in com.pri.factorytest
Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a ”com.pri.factorytest.emmc.FactoryResetService“ s…
4.3
CVE-2024-7097 - Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User…
An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper au…
4.2
CVE-2024-7096 - Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible to the attacker. …
3.1
CVE-2025-3611 - Improper Access Control in Mattermost allows System Managers to view team details despite role rest…
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team e…
5.4
CVE-2025-3230 - Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previo…