Vulnerabilities (CVE)

Filtered by CWE-276
Total 1321 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48822 2025-03-18 N/A 8.8 HIGH
Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.
CVE-2021-34182 1 Ttyd Project 1 Ttyd 2025-03-18 N/A 9.8 CRITICAL
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
CVE-2021-34164 1 Lizhifaka Project 1 Lizhifaka 2025-03-18 N/A 8.8 HIGH
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin/index/email location.
CVE-2021-37000 1 Huawei 1 Harmonyos 2025-03-18 N/A 7.7 HIGH
Some Huawei wearables have a permission management vulnerability.
CVE-2024-55959 2025-03-18 N/A 9.1 CRITICAL
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
CVE-2024-44151 1 Apple 1 Macos 2025-03-18 N/A 5.5 MEDIUM
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system.
CVE-2024-40792 1 Apple 1 Macos 2025-03-18 N/A 3.3 LOW
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app may be able to change network settings.
CVE-2024-10469 1 Cert 1 Vince 2025-03-17 N/A 6.5 MEDIUM
VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.
CVE-2024-51162 2025-03-17 N/A 8.8 HIGH
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes of any user, ongoing audit data and more.
CVE-2024-48823 2025-03-15 N/A 9.8 CRITICAL
Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page.
CVE-2024-55957 2025-03-14 N/A 7.8 HIGH
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems.
CVE-2024-25654 1 Avsystem 1 Unified Management Platform 2025-03-14 N/A 5.5 MEDIUM
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.
CVE-2024-30977 2025-03-13 N/A 7.8 HIGH
An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.
CVE-2024-44228 1 Apple 1 Xcode 2025-03-13 N/A 7.5 HIGH
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
CVE-2023-52545 1 Huawei 2 Emui, Harmonyos 2025-03-13 N/A 7.5 HIGH
Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-44786 2025-03-13 N/A 7.5 HIGH
Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.
CVE-2024-30415 1 Huawei 2 Emui, Harmonyos 2025-03-13 N/A 9.1 CRITICAL
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2023-52717 1 Huawei 2 Emui, Harmonyos 2025-03-13 N/A 5.3 MEDIUM
Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2023-52362 1 Huawei 2 Emui, Harmonyos 2025-03-13 N/A 7.5 HIGH
Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.
CVE-2025-27926 2025-03-10 N/A 4.3 MEDIUM
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.