Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 5.5 CVE-2025-24790 Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered an… Snowflake Jdbc 3.22.0+ Fix from $1,6002025-01-29 MEDIUM 6.7 CVE-2025-24826 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625. Mitigation only Fix from $1,6002025-01-28 CRITICAL 9.1 CVE-2024-57548 CMSimple 5.16 allows the user to edit log.php file via print page. Cmsimple No fix yet Fix from $2,3002025-01-27 HIGH 7.1 CVE-2025-24176 A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A l… macOS 13.7.3 / 14.7.3+ Fix from $1,9502025-01-27 HIGH 7.8 CVE-2025-24135 This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges. macOS 15.3+ Fix from $1,9502025-01-27 MEDIUM 5.3 CVE-2025-24140 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not hav… macOS 15.3+ Fix from $1,6002025-01-27 HIGH 7.8 CVE-2025-24107 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, watch… Ipados 11.3 / 15.3+ Fix from $1,9502025-01-27 CRITICAL 9.8 CVE-2025-24093 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.3, macOS Ventura 13.7.3.… macOS 13.7.3 / 14.7.3+ Fix from $2,3002025-01-27 HIGH 7.8 CVE-2025-0542 Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vul… Mitigation only Fix from $1,9502025-01-25 HIGH 7.8 CVE-2025-0543 Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unp… Mitigation only Fix from $1,9502025-01-25 CRITICAL 9.8 CVE-2024-55930 Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files Workplace Suite 5.6.701.9+ Fix from $2,3002025-01-23 HIGH 7.8 CVE-2024-55957 In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages hav… Mitigation only Fix from $1,9502025-01-22 HIGH 8.8 CVE-2025-24399 Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive,… Openid Connect Authentication 4.438.440.v3f5f201de5dc / 4.453.v4d7765c854f4+ Fix from $1,9502025-01-22 HIGH 7.0 CVE-2024-49724 In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race cond… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-49732 In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permi… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-49735 In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of… Android No fix yet Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-49737 In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a lo… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-49744 In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deseri… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-34730 In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-43765 In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation o… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2023-40132 In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permiss… Android Mitigation only Fix from $1,9502025-01-21 HIGH 7.8 CVE-2025-21532 Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.… Analytics Desktop 8.1.0+ Fix from $1,9502025-01-21 CRITICAL 9.1 CVE-2024-55959 Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions. Mitigation only Fix from $2,3002025-01-21 HIGH 7.8 CVE-2018-9401 In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalatio… Android Mitigation only Fix from $1,9502025-01-18 HIGH 7.8 CVE-2018-9434 In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of pri… Android Patch available Fix from $1,9502025-01-17 CRITICAL 9.8 CVE-2024-57684EPSS 14% An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ servic… Dir 816 Firmware Mitigation only Fix from $2,3002025-01-16 MEDIUM 5.1 CVE-2024-52783 Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modifica… Mitigation only Fix from $1,6002025-01-15 HIGH 7.8 CVE-2024-46464 In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer … Mitigation only Fix from $1,9502025-01-09 CRITICAL 9.8 CVE-2024-55225 An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a … Vaultwarden 1.32.5+ Fix from $2,3002025-01-09 CRITICAL 9.1 CVE-2024-46505 Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities. Mitigation only Fix from $2,3002025-01-09