Show filters
296 Total Results
Displaying 1-10 of 296
Sort by:
Attacker Value
Moderate
CVE-2020-0668
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.
1
Attacker Value
Unknown
CVE-2021-25276
Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a user with a C:\ home directory, then the attacker obtains access to read or replace arbitrary files with LocalSystem privileges.
3
Attacker Value
High
CVE-2020-1170
Disclosure Date: June 09, 2020 (last updated February 21, 2025)
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.
1
Attacker Value
Low
CVE-2020-13386
Disclosure Date: May 27, 2020 (last updated February 21, 2025)
In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the SmartDraw 2020 installation folder. Additionally, when the product is installed, two scheduled tasks are created on the machine, SDMsgUpdate (Local) and SDMsgUpdate (TE). The scheduled tasks run in the context of the user who installed the product. Both scheduled tasks attempt to run the same binary, C:\SmartDraw 2020\Messages\SDNotify.exe. The folder Messages doesn't exist by default and (by extension) neither does SDNotify.exe. Due to the weak folder permissions, these can be created by any user. A malicious actor can therefore create a malicious SDNotify.exe binary, and have it automatically run, whenever the user who installed the product logs on to the machine. The malicious SDNotify.exe could, for example, create a new local administrator account on the machine.
0
Attacker Value
Unknown
CVE-2021-40067
Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v12.14.
0
Attacker Value
Unknown
CVE-2021-40066
Disclosure Date: September 16, 2021 (last updated February 23, 2025)
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.
0
Attacker Value
Unknown
CVE-2021-39210
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.
0
Attacker Value
Unknown
CVE-2021-22147
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
0
Attacker Value
Unknown
CVE-2021-26434
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Visual Studio Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-22149
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.
0