Vulnerabilities (CVE)

Filtered by CWE-276
Total 1379 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0426 1 Suse 1 Suse Linux 2025-04-03 10.0 HIGH 9.8 CRITICAL
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
CVE-2022-48199 2 Microsoft, Softperfect 2 Windows, Networx 2025-04-02 N/A 8.8 HIGH
SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user account that abuses the Notifications function. The Notifications function allows for arbitrary binary execution and can be modified by any user. The resulting binary execution will occur in the context of any user running NetWorx. If an attacker modifies the Notifications function to execute a malicious binary, the binary will be executed by every user running NetWorx on that system.
CVE-2022-47040 1 Askey 2 Rtf3505vw-n1, Rtf3505vw-n1 Firmware 2025-04-02 N/A 7.8 HIGH
An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after placing a crafted file in the /tmp directory and sending crafted packets through port 80.
CVE-2022-20456 1 Google 1 Android 2025-04-02 N/A 7.8 HIGH
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703780
CVE-2025-2781 2025-04-01 N/A N/A
The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Mobile VPN with SSL Client: from 11.0 through 12.11.
CVE-2025-2782 2025-04-01 N/A N/A
The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Terminal Services Agent: from 12.0 through 12.10.
CVE-2024-53351 1 Linuxfoundation 1 Pipecd 2025-04-01 N/A 9.8 CRITICAL
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
CVE-2023-46270 2025-03-28 N/A 3.3 LOW
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.
CVE-2024-26574 1 Wondershare 1 Filmora 2025-03-28 N/A 7.8 HIGH
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe
CVE-2025-25535 2025-03-27 N/A 9.8 CRITICAL
HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.
CVE-2022-23454 1 Hp 1 Support Assistant 2025-03-27 N/A 7.8 HIGH
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.
CVE-2022-23453 1 Hp 1 Support Assistant 2025-03-27 N/A 7.8 HIGH
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.
CVE-2024-26302 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-27 N/A 4.8 MEDIUM
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.
CVE-2024-6148 1 Citrix 1 Workspace 2025-03-25 N/A 8.8 HIGH
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
CVE-2024-54564 1 Apple 4 Ipados, Iphone Os, Macos and 1 more 2025-03-25 N/A 6.5 MEDIUM
This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.
CVE-2024-51440 2025-03-22 N/A 7.8 HIGH
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
CVE-2023-1809 1 W3eden 1 Download Manager 2025-03-21 N/A 7.5 HIGH
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
CVE-2025-27612 2025-03-21 N/A 5.9 MEDIUM
libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of capabilities to be added in the spec of tenant container. The logic here adds the given capabilities to all capabilities of main container if present in spec, otherwise simply set provided capabilities as capabilities of the tenant container. However, setting inherited caps in any case for tenant container can lead to elevation of capabilities, similar to CVE-2022-29162. This does not affect youki binary itself. This is only applicable if you are using libcontainer directly and using the tenant builder.
CVE-2025-24915 2025-03-21 N/A 7.8 HIGH
When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories.  This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
CVE-2023-29162 2025-03-20 N/A 6.0 MEDIUM
Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.