Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Unclassified HIGH 7.5
CVE-2024-36063

The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone ca…

Mitigation only
Fix from $1,950 2024-11-07
Unclassified CRITICAL 9.1
CVE-2019-20457

An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication,…

Mitigation only
Fix from $2,300 2024-11-07
Unclassified HIGH 8.8
CVE-2019-20458

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The use…

Mitigation only
Fix from $1,950 2024-11-07
Unclassified HIGH 8.8
CVE-2020-11921

An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth …

Mitigation only
Fix from $1,950 2024-11-07
Android HIGH 7.1
CVE-2024-34679

Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

Mitigation only
Fix from $1,950 2024-11-06
Verify HIGH 7.8
CVE-2024-9191

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers …

Fix: 5.3.3+
Fix from $1,950 2024-11-01
Aquilacms MEDIUM 5.3
CVE-2024-48572

A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feat…

Fix: after 1.409.20
Fix from $1,600 2024-10-29
Xcode HIGH 7.5
CVE-2024-44228

This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and acc…

Fix: 16.0+
Fix from $1,950 2024-10-28
Vince MEDIUM 6.5
CVE-2024-10469

VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.

Fix: 3.0.9+
Fix from $1,600 2024-10-28
Unclassified HIGH 8.8
CVE-2024-42028

A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) al…

Mitigation only
Fix from $1,950 2024-10-28
Ovaledge CRITICAL 9.8
CVE-2022-30355

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email p…

Fix: 5.2.9+
Fix from $2,300 2024-10-25
Android HIGH 7.5
CVE-2024-44100

Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.

Fix: 2024-10-05+
Fix from $1,950 2024-10-25
Android HIGH 7.8
CVE-2024-47012

In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to l…

Mitigation only
Fix from $1,950 2024-10-25
Android HIGH 7.8
CVE-2024-47013

In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation…

Mitigation only
Fix from $1,950 2024-10-25
Android HIGH 8.8
CVE-2024-47014

Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.

Mitigation only
Fix from $1,950 2024-10-25
Android HIGH 7.8
CVE-2024-47016

there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execut…

No fix yet
Fix from $1,950 2024-10-25
Profilepress CRITICAL 9.8
CVE-2024-9947

The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insuffi…

Fix: 4.11.2+
Fix from $2,300 2024-10-23
Genesis64 HIGH 7.8
CVE-2024-7587

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 an…

Fix: after 10.97.3
Fix from $1,950 2024-10-22
Unclassified MEDIUM 5.2
CVE-2024-10183

A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems.

Mitigation only
Fix from $1,600 2024-10-22
Micollab MEDIUM 6.7
CVE-2024-35287

A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker wi…

Fix: after 9.8.1.5
Fix from $1,600 2024-10-21
Cilium HIGH 8.7
CVE-2024-47825

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 a…

Fix: 1.14.16 / 1.15.10+
Fix from $1,950 2024-10-21
Secure Connect Gateway MEDIUM 6.3
CVE-2024-47240

Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the f…

No fix yet
Fix from $1,600 2024-10-18
Cyber Files HIGH 7.8
CVE-2024-49389

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x…

Fix: 9.0+
Fix from $1,950 2024-10-17
Migrate To Containers HIGH 7.8
CVE-2024-9858

There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser…

Fix: 1.2.3+
Fix from $1,950 2024-10-16
Unclassified HIGH 8.8
CVE-2024-48822

Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate pr…

Mitigation only
Fix from $1,950 2024-10-14
Unclassified CRITICAL 9.8
CVE-2024-48823

Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate pr…

Mitigation only
Fix from $2,300 2024-10-14
Dolby Vision Provisioning MEDIUM 5.5
CVE-2024-5474

A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 th…

Fix: 2.0.0.2+
Fix from $1,600 2024-10-11
Junos Os Evolved MEDIUM 5.0
CVE-2024-39544

An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local…

Fix: 20.4+
Fix from $1,600 2024-10-11
Unclassified MEDIUM 6.7
CVE-2023-42133

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system ac…

Mitigation only
Fix from $1,600 2024-10-11
Velocity License Server HIGH 7.8
CVE-2024-9167

Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achi…

Fix: 5.2+
Fix from $1,950 2024-10-08