Total
1261 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-39924 | 2025-03-18 | N/A | 8.8 HIGH | ||
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period. | |||||
CVE-2023-23850 | 1 Jenkins | 1 Synopsys Coverity | 2025-03-18 | N/A | 4.3 MEDIUM |
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
CVE-2023-23848 | 1 Jenkins | 1 Synopsys Coverity | 2025-03-18 | N/A | 4.3 MEDIUM |
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |||||
CVE-2024-48822 | 2025-03-18 | N/A | 8.8 HIGH | ||
Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page. | |||||
CVE-2021-34182 | 1 Ttyd Project | 1 Ttyd | 2025-03-18 | N/A | 9.8 CRITICAL |
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions. | |||||
CVE-2021-34164 | 1 Lizhifaka Project | 1 Lizhifaka | 2025-03-18 | N/A | 8.8 HIGH |
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin/index/email location. | |||||
CVE-2021-37000 | 1 Huawei | 1 Harmonyos | 2025-03-18 | N/A | 7.7 HIGH |
Some Huawei wearables have a permission management vulnerability. | |||||
CVE-2025-24399 | 2025-03-18 | N/A | 8.8 HIGH | ||
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins. | |||||
CVE-2024-55959 | 2025-03-18 | N/A | 9.1 CRITICAL | ||
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions. | |||||
CVE-2024-44151 | 1 Apple | 1 Macos | 2025-03-18 | N/A | 5.5 MEDIUM |
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system. | |||||
CVE-2024-40792 | 1 Apple | 1 Macos | 2025-03-18 | N/A | 3.3 LOW |
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app may be able to change network settings. | |||||
CVE-2024-10469 | 1 Cert | 1 Vince | 2025-03-17 | N/A | 6.5 MEDIUM |
VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users. | |||||
CVE-2024-51162 | 2025-03-17 | N/A | 8.8 HIGH | ||
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes of any user, ongoing audit data and more. | |||||
CVE-2024-48823 | 2025-03-15 | N/A | 9.8 CRITICAL | ||
Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page. | |||||
CVE-2024-55957 | 2025-03-14 | N/A | 7.8 HIGH | ||
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems. | |||||
CVE-2024-25654 | 1 Avsystem | 1 Unified Management Platform | 2025-03-14 | N/A | 5.5 MEDIUM |
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database. | |||||
CVE-2024-30977 | 2025-03-13 | N/A | 7.8 HIGH | ||
An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component. | |||||
CVE-2024-44228 | 1 Apple | 1 Xcode | 2025-03-13 | N/A | 7.5 HIGH |
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data. | |||||
CVE-2023-52545 | 1 Huawei | 2 Emui, Harmonyos | 2025-03-13 | N/A | 7.5 HIGH |
Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability. | |||||
CVE-2024-44786 | 2025-03-13 | N/A | 7.5 HIGH | ||
Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors. |