Show filters
1,213 Total Results
Displaying 31-40 of 1,213
Sort by:
Attacker Value
Unknown
CVE-2025-24826
Disclosure Date: January 28, 2025 (last updated February 27, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.
0
Attacker Value
Unknown
CVE-2024-57548
Disclosure Date: January 27, 2025 (last updated February 27, 2025)
CMSimple 5.16 allows the user to edit log.php file via print page.
0
Attacker Value
Unknown
CVE-2025-24176
Disclosure Date: January 27, 2025 (last updated February 27, 2025)
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privileges.
0
Attacker Value
Unknown
CVE-2025-24140
Disclosure Date: January 27, 2025 (last updated February 27, 2025)
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the quarantine flag applied.
0
Attacker Value
Unknown
CVE-2025-24107
Disclosure Date: January 27, 2025 (last updated February 27, 2025)
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3, iOS 18.3 and iPadOS 18.3. A malicious app may be able to gain root privileges.
0
Attacker Value
Unknown
CVE-2025-0543
Disclosure Date: January 25, 2025 (last updated February 27, 2025)
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the SetupSVC.exe service in the context of SYSTEM.
0
Attacker Value
Unknown
CVE-2025-0542
Disclosure Date: January 25, 2025 (last updated February 27, 2025)
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writable directory, which gets unpacked in the context of SYSTEM and results in arbitrary file write.
0
Attacker Value
Unknown
CVE-2024-55930
Disclosure Date: January 23, 2025 (last updated February 25, 2025)
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files
0
Attacker Value
Unknown
CVE-2025-20156
Disclosure Date: January 22, 2025 (last updated February 27, 2025)
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device.
This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this vulnerability by sending API requests to a specific endpoint. A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management.
0
Attacker Value
Unknown
CVE-2024-34730
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0