Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
CRITICAL 9.8 CVE-2024-54745 WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. Wn701ae Firmware No fix yet Fix from $2,3002024-12-06 CRITICAL 9.8 CVE-2024-54747 WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. Wn531p3 Firmware No fix yet Fix from $2,3002024-12-06 HIGH 8.8 CVE-2024-46624 An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /ap… Mitigation only Fix from $1,9502024-12-03 HIGH 7.3 CVE-2024-54131 The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as… Patch available Fix from $1,9502024-12-03 HIGH 7.8 CVE-2018-9431 In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of priv… Android Patch available Fix from $1,9502024-12-02 HIGH 8.8 CVE-2024-11969 The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user… Mitigation only Fix from $1,9502024-11-28 CRITICAL 9.8 CVE-2024-46054 OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload file… Openvidreview Mitigation only Fix from $2,3002024-11-27 HIGH 7.0 CVE-2024-27134 Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacke… Mlflow 2.16.0+ Fix from $1,9502024-11-25 MEDIUM 6.8 CVE-2024-50657 An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically … Mitigation only Fix from $1,6002024-11-22 HIGH 7.5 CVE-2024-44786 Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors. Mitigation only Fix from $1,9502024-11-22 HIGH 7.5 CVE-2024-11088 The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPr… Simple Membership 4.5.6+ Fix from $1,9502024-11-21 MEDIUM 5.3 CVE-2024-11089 The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via… Anonymous Restricted Content 1.6.6+ Fix from $1,6002024-11-21 MEDIUM 5.3 CVE-2024-48533 A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attacke… Esoft Planner No fix yet Fix from $1,6002024-11-20 HIGH 8.8 CVE-2024-51162 An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was iden… Mitigation only Fix from $1,9502024-11-20 HIGH 7.5 CVE-2024-45690 A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts. Moodle 4.1.13 / 4.2.10+ Fix from $1,9502024-11-20 CRITICAL 9.8 CVE-2018-9467 In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security deci… Android Mitigation only Fix from $2,3002024-11-20 HIGH 7.8 CVE-2018-9432 In createPhonebookDialogView and createMapDialogView of BluetoothPermissionActivity.java, there is a possible permissions bypass. This could lead to … Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.3 CVE-2018-9369 In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilege with … Android Mitigation only Fix from $1,9502024-11-19 HIGH 7.8 CVE-2023-21270 In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to … Android Patch available Fix from $1,9502024-11-19 CRITICAL 9.8 CVE-2024-51051 AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account. Mitigation only Fix from $2,3002024-11-18 MEDIUM 6.5 CVE-2024-48293 Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily mo… Mitigation only Fix from $1,6002024-11-18 HIGH 8.8 CVE-2024-48292 An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to esc… Mitigation only Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-28058 In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal t… Mitigation only Fix from $1,9502024-11-18 HIGH 8.8 CVE-2024-52946 An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authenti… Mitigation only Fix from $1,9502024-11-18 MEDIUM 6.5 CVE-2024-52926 Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent. No fix yet Fix from $1,6002024-11-18 HIGH 8.1 CVE-2024-52867 guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns … Mitigation only Fix from $1,9502024-11-17 MEDIUM 5.5 CVE-2024-51764 A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may … No fix yet Fix from $1,6002024-11-15 MEDIUM 5.5 CVE-2024-51765 A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead t… Mitigation only Fix from $1,6002024-11-15 HIGH 7.8 CVE-2017-13310 In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local e… Android Mitigation only Fix from $1,9502024-11-15 MEDIUM 6.7 CVE-2017-13311 In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to l… Android Mitigation only Fix from $1,6002024-11-15