Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,544 CVEs tagged with CWE-276119 Critical, 742 High, 618 Medium, 65 Low, 0 Unrated.

CVE-2021-27285

Published Jan 6, 2025

An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsBySh…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53841

Published Jan 3, 2025

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional executi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53840

Published Jan 3, 2025

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53835

Published Jan 3, 2025

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11624

Published Jan 3, 2025

there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional execution privileges needed. User…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43769

Published Jan 3, 2025

In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This coul…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55950

Published Dec 26, 2024

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for it…

CVSS 8.6 · High

CVE-2024-12903

Published Dec 23, 2024

Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges…

CVSS 7.8 · High

CVE-2024-45819

Published Dec 19, 2024

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While act…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4229

Published Dec 19, 2024

Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later all…

CVSS 7.8 · High

CVE-2024-49202

Published Dec 18, 2024

Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6…

CVSS 7.6 · High

CVE-2024-38499

Published Dec 17, 2024

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryptio…

CVSS 7.3 · High

CVE-2024-12564

Published Dec 12, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installing CDE Server with default set…

CVSS 6.9 · Medium

CVE-2024-44224

Published Dec 12, 2024

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app may be able t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11872

Published Dec 12, 2024

Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9845

Published Dec 11, 2024

Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8496

Published Dec 11, 2024

Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalatio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11598

Published Dec 11, 2024

Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11597

Published Dec 11, 2024

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10251

Published Dec 11, 2024

Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45494

Published Dec 10, 2024

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account on all d…

CVSS 9.8 · Critical

CVE-2024-54751

Published Dec 10, 2024

COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

CVSS 9.8 · Critical
Showing 351-375 of 1,544 CVEsPage 15 of 62