Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Snowflake Jdbc MEDIUM 5.5
CVE-2025-24790

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered an…

Fix: 3.22.0+
Fix from $1,600 2025-01-29
Unclassified MEDIUM 6.7
CVE-2025-24826

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.

Mitigation only
Fix from $1,600 2025-01-28
Cmsimple CRITICAL 9.1
CVE-2024-57548

CMSimple 5.16 allows the user to edit log.php file via print page.

No fix yet
Fix from $2,300 2025-01-27
macOS HIGH 7.1
CVE-2025-24176

A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A l…

Fix: 13.7.3 / 14.7.3+
Fix from $1,950 2025-01-27
macOS HIGH 7.8
CVE-2025-24135

This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges.

Fix: 15.3+
Fix from $1,950 2025-01-27
macOS MEDIUM 5.3
CVE-2025-24140

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not hav…

Fix: 15.3+
Fix from $1,600 2025-01-27
Ipados HIGH 7.8
CVE-2025-24107

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, watch…

Fix: 11.3 / 15.3+
Fix from $1,950 2025-01-27
macOS CRITICAL 9.8
CVE-2025-24093

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.3, macOS Ventura 13.7.3.…

Fix: 13.7.3 / 14.7.3+
Fix from $2,300 2025-01-27
Unclassified HIGH 7.8
CVE-2025-0542

Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vul…

Mitigation only
Fix from $1,950 2025-01-25
Unclassified HIGH 7.8
CVE-2025-0543

Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unp…

Mitigation only
Fix from $1,950 2025-01-25
Workplace Suite CRITICAL 9.8
CVE-2024-55930

Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files

Fix: 5.6.701.9+
Fix from $2,300 2025-01-23
Unclassified HIGH 7.8
CVE-2024-55957

In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages hav…

Mitigation only
Fix from $1,950 2025-01-22
Openid Connect Authentication HIGH 8.8
CVE-2025-24399

Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive,…

Fix: 4.438.440.v3f5f201de5dc / 4.453.v4d7765c854f4+
Fix from $1,950 2025-01-22
Android HIGH 7.0
CVE-2024-49724

In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race cond…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-49732

In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permi…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-49735

In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of…

No fix yet
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-49737

In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a lo…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-49744

In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deseri…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-34730

In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2024-43765

In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2025-01-21
Android HIGH 7.8
CVE-2023-40132

In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permiss…

Mitigation only
Fix from $1,950 2025-01-21
Analytics Desktop HIGH 7.8
CVE-2025-21532

Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.…

Fix: 8.1.0+
Fix from $1,950 2025-01-21
Unclassified CRITICAL 9.1
CVE-2024-55959

Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.

Mitigation only
Fix from $2,300 2025-01-21
Android HIGH 7.8
CVE-2018-9401

In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2025-01-18
Android HIGH 7.8
CVE-2018-9434

In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of pri…

Patch available
Fix from $1,950 2025-01-17
Dir 816 Firmware CRITICAL 9.8
CVE-2024-57684EPSS 14%

An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ servic…

Mitigation only
Fix from $2,300 2025-01-16
Unclassified MEDIUM 5.1
CVE-2024-52783

Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modifica…

Mitigation only
Fix from $1,600 2025-01-15
Unclassified HIGH 7.8
CVE-2024-46464

In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer …

Mitigation only
Fix from $1,950 2025-01-09
Vaultwarden CRITICAL 9.8
CVE-2024-55225

An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a …

Fix: 1.32.5+
Fix from $2,300 2025-01-09
Unclassified CRITICAL 9.1
CVE-2024-46505

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

Mitigation only
Fix from $2,300 2025-01-09