Show filters
1,213 Total Results
Displaying 31-40 of 1,213
Sort by:
Attacker Value
Unknown

CVE-2025-24826

Disclosure Date: January 28, 2025 (last updated February 27, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.
0
Attacker Value
Unknown

CVE-2024-57548

Disclosure Date: January 27, 2025 (last updated February 27, 2025)
CMSimple 5.16 allows the user to edit log.php file via print page.
0
Attacker Value
Unknown

CVE-2025-24176

Disclosure Date: January 27, 2025 (last updated February 27, 2025)
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privileges.
0
Attacker Value
Unknown

CVE-2025-24140

Disclosure Date: January 27, 2025 (last updated February 27, 2025)
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the quarantine flag applied.
Attacker Value
Unknown

CVE-2025-24107

Disclosure Date: January 27, 2025 (last updated February 27, 2025)
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3, iOS 18.3 and iPadOS 18.3. A malicious app may be able to gain root privileges.
Attacker Value
Unknown

CVE-2025-0543

Disclosure Date: January 25, 2025 (last updated February 27, 2025)
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the SetupSVC.exe service in the context of SYSTEM.
0
Attacker Value
Unknown

CVE-2025-0542

Disclosure Date: January 25, 2025 (last updated February 27, 2025)
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writable directory, which gets unpacked in the context of SYSTEM and results in arbitrary file write.
0
Attacker Value
Unknown

CVE-2024-55930

Disclosure Date: January 23, 2025 (last updated February 25, 2025)
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files
0
Attacker Value
Unknown

CVE-2025-20156

Disclosure Date: January 22, 2025 (last updated February 27, 2025)
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this vulnerability by sending API requests to a specific endpoint. A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management.
0
Attacker Value
Unknown

CVE-2024-34730

Disclosure Date: January 21, 2025 (last updated February 27, 2025)
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
0