6.5

CVSS3.1

CVE-2024-42191 - HCL Traveler for Microsoft Outlook (HTMO) is susceptible to COM hijacking

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

📅 Published: May 30, 2025, 3:54 p.m. 🔄 Last Modified: Oct. 30, 2025, 3:56 p.m.

6.5

CVSS3.1

CVE-2024-42190 - HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

📅 Published: May 30, 2025, 3:51 p.m. 🔄 Last Modified: Oct. 30, 2025, 3:58 p.m.

6.8

CVSS3.1

CVE-2024-23589 - HCL Glovius Cloud is susceptible to an Outdated Hash Algorithm vulnerability

Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs

📅 Published: May 30, 2025, 3:36 p.m. 🔄 Last Modified: May 30, 2025, 4:31 p.m.

8.3

CVSS4.0

CVE-2024-13917 - Intent Injection in Kruger&Matz AppLock application

An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permis…

📅 Published: May 30, 2025, 3:17 p.m. 🔄 Last Modified: June 10, 2025, 10:15 a.m.

6.9

CVSS4.0

CVE-2024-13916 - Exposure of Applications' Encryption PINs in Kruger&Matz AppLock

An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider's public method query() allows…

📅 Published: May 30, 2025, 3:16 p.m. 🔄 Last Modified: Oct. 3, 2025, 9:15 a.m.

6.9

CVSS4.0

CVE-2024-13915 - Unrestricted Access to Exported Service in com.pri.factorytest

Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a ”com.pri.factorytest.emmc.FactoryResetService“ s…

📅 Published: May 30, 2025, 3:09 p.m. 🔄 Last Modified: June 10, 2025, 9:15 a.m.

4.3

CVSS3.1

CVE-2024-7097 - Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User…

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper au…

📅 Published: May 30, 2025, 3:04 p.m. 🔄 Last Modified: Oct. 6, 2025, 1:51 p.m.

4.2

CVSS3.1

CVE-2024-7096 - Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible to the attacker. …

📅 Published: May 30, 2025, 2:54 p.m. 🔄 Last Modified: Dec. 3, 2025, 8:15 a.m.

3.1

CVSS3.1

CVE-2025-3611 - Improper Access Control in Mattermost allows System Managers to view team details despite role rest…

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team e…

📅 Published: May 30, 2025, 2:22 p.m. 🔄 Last Modified: July 8, 2025, 5:11 p.m.

5.4

CVSS3.1

CVE-2025-3230 - Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previo…

📅 Published: May 30, 2025, 2:22 p.m. 🔄 Last Modified: Oct. 15, 2025, 2:16 p.m.
Total resulsts: 343943
Page 4693 of 34,395
« previous page » next page
Filters