Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Wn701ae Firmware CRITICAL 9.8
CVE-2024-54745

WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

No fix yet
Fix from $2,300 2024-12-06
Wn531p3 Firmware CRITICAL 9.8
CVE-2024-54747

WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

No fix yet
Fix from $2,300 2024-12-06
Unclassified HIGH 8.8
CVE-2024-46624

An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /ap…

Mitigation only
Fix from $1,950 2024-12-03
Unclassified HIGH 7.3
CVE-2024-54131

The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as…

Patch available
Fix from $1,950 2024-12-03
Android HIGH 7.8
CVE-2018-9431

In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of priv…

Patch available
Fix from $1,950 2024-12-02
Unclassified HIGH 8.8
CVE-2024-11969

The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user…

Mitigation only
Fix from $1,950 2024-11-28
Openvidreview CRITICAL 9.8
CVE-2024-46054

OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload file…

Mitigation only
Fix from $2,300 2024-11-27
Mlflow HIGH 7.0
CVE-2024-27134

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacke…

Fix: 2.16.0+
Fix from $1,950 2024-11-25
Unclassified MEDIUM 6.8
CVE-2024-50657

An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically …

Mitigation only
Fix from $1,600 2024-11-22
Unclassified HIGH 7.5
CVE-2024-44786

Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

Mitigation only
Fix from $1,950 2024-11-22
Simple Membership HIGH 7.5
CVE-2024-11088

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPr…

Fix: 4.5.6+
Fix from $1,950 2024-11-21
Anonymous Restricted Content MEDIUM 5.3
CVE-2024-11089

The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via…

Fix: 1.6.6+
Fix from $1,600 2024-11-21
Esoft Planner MEDIUM 5.3
CVE-2024-48533

A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attacke…

No fix yet
Fix from $1,600 2024-11-20
Unclassified HIGH 8.8
CVE-2024-51162

An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was iden…

Mitigation only
Fix from $1,950 2024-11-20
Moodle HIGH 7.5
CVE-2024-45690

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

Fix: 4.1.13 / 4.2.10+
Fix from $1,950 2024-11-20
Android CRITICAL 9.8
CVE-2018-9467

In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security deci…

Mitigation only
Fix from $2,300 2024-11-20
Android HIGH 7.8
CVE-2018-9432

In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to …

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.3
CVE-2018-9369

In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,950 2024-11-19
Android HIGH 7.8
CVE-2023-21270

In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to …

Patch available
Fix from $1,950 2024-11-19
Unclassified CRITICAL 9.8
CVE-2024-51051

AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.

Mitigation only
Fix from $2,300 2024-11-18
Unclassified MEDIUM 6.5
CVE-2024-48293

Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily mo…

Mitigation only
Fix from $1,600 2024-11-18
Unclassified HIGH 8.8
CVE-2024-48292

An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to esc…

Mitigation only
Fix from $1,950 2024-11-18
Unclassified HIGH 7.5
CVE-2024-28058

In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal t…

Mitigation only
Fix from $1,950 2024-11-18
Unclassified HIGH 8.8
CVE-2024-52946

An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authenti…

Mitigation only
Fix from $1,950 2024-11-18
Unclassified MEDIUM 6.5
CVE-2024-52926

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

No fix yet
Fix from $1,600 2024-11-18
Unclassified HIGH 8.1
CVE-2024-52867

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns …

Mitigation only
Fix from $1,950 2024-11-17
Unclassified MEDIUM 5.5
CVE-2024-51764

A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may …

No fix yet
Fix from $1,600 2024-11-15
Unclassified MEDIUM 5.5
CVE-2024-51765

A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead t…

Mitigation only
Fix from $1,600 2024-11-15
Android HIGH 7.8
CVE-2017-13310

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local e…

Mitigation only
Fix from $1,950 2024-11-15
Android MEDIUM 6.7
CVE-2017-13311

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to l…

Mitigation only
Fix from $1,600 2024-11-15