The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellu...
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain administrator privileges and inje...
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to exe...
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or del...
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that al...
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.