Vulnerabilities (CVE)

Filtered by CWE-862
Total 9920 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-0071 1 Google 1 Android 2026-06-18 N/A 7.8 HIGH
In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48640 1 Google 1 Android 2026-06-18 N/A 8.0 HIGH
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48617 1 Google 1 Android 2026-06-18 N/A 7.8 HIGH
In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-53850 1 Openclaw 1 Openclaw 2026-06-17 N/A 5.5 MEDIUM
OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended caller authority, potentially enabling unauthorized operations depending on gateway configuration and input trust levels.
CVE-2026-53851 1 Openclaw 1 Openclaw 2026-06-17 N/A 5.3 MEDIUM
OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input.
CVE-2026-53844 1 Openclaw 1 Openclaw 2026-06-17 N/A 6.5 MEDIUM
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the search path to retrieve memory entries that should not be visible to their session.
CVE-2026-45085 1 Discourse 1 Discourse 2026-06-17 N/A 5.3 MEDIUM
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in the chat plugin (one also involving discourse-calendar): read-only category users could create chat threads, self-deleted chat messages could be restored by their author after channel access was revoked, moderators reviewing a flagged chat message were shown the channel's current last_message (often unrelated DM content), and calendar event payloads exposed the attached chat channel and its last message to viewers without chat access (including anonymous users). This affects sites with the chat plugin enabled; the calendar issue additionally requires discourse-calendar. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
CVE-2026-54810 2026-06-17 N/A 7.5 HIGH
Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1.
CVE-2026-49072 2026-06-17 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
CVE-2026-45436 2026-06-17 N/A 6.5 MEDIUM
Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
CVE-2026-40723 2026-06-17 N/A 4.3 MEDIUM
Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.
CVE-2026-39595 2026-06-17 N/A 4.7 MEDIUM
Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
CVE-2026-24611 2026-06-17 N/A 9.1 CRITICAL
Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.
CVE-2026-24610 2026-06-17 N/A 4.3 MEDIUM
Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions.
CVE-2025-69189 2026-06-17 N/A 7.3 HIGH
Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.
CVE-2024-37210 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.
CVE-2024-24709 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11.
CVE-2026-0057 1 Google 1 Android 2026-06-17 N/A 3.3 LOW
In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28587 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0133 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.