7.8
CVE-2018-9339 -
In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
6.5
CVE-2024-50430 - WordPress Beaver Builder plugin <= 2.8.3.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Stored XSS.This issue affects Beaver Builder: from n/a through <= 2.8.3.7.
0.0
CVE-2024-53249 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
0.0
CVE-2024-53250 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
0.0
CVE-2024-53252 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
0.0
CVE-2024-53251 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
0.0
CVE-2024-53248 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.
7.8
CVE-2018-9338 -
In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
7.8
CVE-2023-21270 -
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User inteβ¦
7.8
CVE-2017-13315 -
In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not β¦