CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2019-11-22
N/A
3.3 LOW
The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2019-11-22
N/A
3.3 LOW
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2019-11-22
N/A
3.3 LOW
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2020-08-24
N/A
3.3 LOW
The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
