Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,530 CVEs tagged with CWE-276118 Critical, 735 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2024-52783

Published Jan 15, 2025

Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modification of the configuration file.

CVSS 5.1 · Medium

CVE-2024-46464

Published Jan 9, 2025

In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer unavailable or to execute prog…

CVSS 7.8 · High

CVE-2024-55225

Published Jan 9, 2025

An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-1907

Published Jan 9, 2025

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13206

Published Jan 9, 2025

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The ma…

CVSS 8.5 · High

CVE-2024-13188

Published Jan 8, 2025

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functionality of the file /opt/Micro…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56447

Published Jan 8, 2025

Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41572

Published Jan 7, 2025

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27285

Published Jan 6, 2025

An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsBySh…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53841

Published Jan 3, 2025

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional executi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53840

Published Jan 3, 2025

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53835

Published Jan 3, 2025

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11624

Published Jan 3, 2025

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional execution privileges needed. User…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43769

Published Jan 3, 2025

In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This coul…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55950

Published Dec 26, 2024

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for it…

CVSS 8.6 · High

CVE-2024-12903

Published Dec 23, 2024

Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges…

CVSS 7.8 · High

CVE-2024-45819

Published Dec 19, 2024

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While act…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4229

Published Dec 19, 2024

Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later all…

CVSS 7.8 · High

CVE-2024-49202

Published Dec 18, 2024

Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6…

CVSS 7.6 · High

CVE-2024-38499

Published Dec 17, 2024

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryptio…

CVSS 7.3 · High

CVE-2024-12564

Published Dec 12, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installing CDE Server with default set…

CVSS 6.9 · Medium
Showing 326-350 of 1,530 CVEsPage 14 of 62