Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.5 CVE-2024-36063 The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone ca… Mitigation only Fix from $1,9502024-11-07 CRITICAL 9.1 CVE-2019-20457 An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication,… Mitigation only Fix from $2,3002024-11-07 HIGH 8.8 CVE-2019-20458 An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The use… Mitigation only Fix from $1,9502024-11-07 HIGH 8.8 CVE-2020-11921 An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth … Mitigation only Fix from $1,9502024-11-07 HIGH 7.1 CVE-2024-34679 Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege. Android Mitigation only Fix from $1,9502024-11-06 HIGH 7.8 CVE-2024-9191 The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers … Verify 5.3.3+ Fix from $1,9502024-11-01 MEDIUM 5.3 CVE-2024-48572 A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feat… Aquilacms after 1.409.20 Fix from $1,6002024-10-29 HIGH 7.5 CVE-2024-44228 This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and acc… Xcode 16.0+ Fix from $1,9502024-10-28 MEDIUM 6.5 CVE-2024-10469 VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users. Vince 3.0.9+ Fix from $1,6002024-10-28 HIGH 8.8 CVE-2024-42028 A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) al… Mitigation only Fix from $1,9502024-10-28 CRITICAL 9.8 CVE-2022-30355 OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email p… Ovaledge 5.2.9+ Fix from $2,3002024-10-25 HIGH 7.5 CVE-2024-44100 Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545. Android 2024-10-05+ Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-47012 In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to l… Android Mitigation only Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-47013 In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation… Android Mitigation only Fix from $1,9502024-10-25 HIGH 8.8 CVE-2024-47014 Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292. Android Mitigation only Fix from $1,9502024-10-25 HIGH 7.8 CVE-2024-47016 there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execut… Android No fix yet Fix from $1,9502024-10-25 CRITICAL 9.8 CVE-2024-9947 The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insuffi… Profilepress 4.11.2+ Fix from $2,3002024-10-23 HIGH 7.8 CVE-2024-7587 Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 an… Genesis64 after 10.97.3 Fix from $1,9502024-10-22 MEDIUM 5.2 CVE-2024-10183 A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems. Mitigation only Fix from $1,6002024-10-22 MEDIUM 6.7 CVE-2024-35287 A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker wi… Micollab after 9.8.1.5 Fix from $1,6002024-10-21 HIGH 8.7 CVE-2024-47825 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.16 a… Cilium 1.14.16 / 1.15.10+ Fix from $1,9502024-10-21 MEDIUM 6.3 CVE-2024-47240 Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with low privileges can access the f… Secure Connect Gateway No fix yet Fix from $1,6002024-10-18 HIGH 7.8 CVE-2024-49389 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x… Cyber Files 9.0+ Fix from $1,9502024-10-17 HIGH 7.8 CVE-2024-9858 There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser… Migrate To Containers 1.2.3+ Fix from $1,9502024-10-16 HIGH 8.8 CVE-2024-48822 Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate pr… Mitigation only Fix from $1,9502024-10-14 CRITICAL 9.8 CVE-2024-48823 Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate pr… Mitigation only Fix from $2,3002024-10-14 MEDIUM 5.5 CVE-2024-5474 A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 th… Dolby Vision Provisioning 2.0.0.2+ Fix from $1,6002024-10-11 MEDIUM 5.0 CVE-2024-39544 An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local… Junos Os Evolved 20.4+ Fix from $1,6002024-10-11 MEDIUM 6.7 CVE-2023-42133 PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system ac… Mitigation only Fix from $1,6002024-10-11 HIGH 7.8 CVE-2024-9167 Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achi… Velocity License Server 5.2+ Fix from $1,9502024-10-08