Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to exe...
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malfo...
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or del...
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that al...
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive s...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.