Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 2183 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-19791 1 Lemonldap-ng 1 Lemonldap\ 2025-01-14 N/A 9.8 CRITICAL
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive.
CVE-2024-49112 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-14 N/A 9.8 CRITICAL
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2023-29741 1 Bestweather Project 1 Bestweather 2025-01-14 N/A 9.8 CRITICAL
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database.
CVE-2023-29739 1 Amdroidapp 1 Alarm Clock For Heavy Sleepers 2025-01-14 N/A 9.8 CRITICAL
An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.
CVE-2023-29728 1 Applika 1 Call Blocker 2025-01-13 N/A 9.8 CRITICAL
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.
CVE-2022-36246 1 Shopbeat 1 Shop Beat Media Player 2025-01-13 N/A 9.8 CRITICAL
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.
CVE-2023-29727 1 Applika 1 Call Blocker 2025-01-13 N/A 9.8 CRITICAL
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of privilege attack.
CVE-2023-34257 1 Bmc 1 Patrol 2025-01-10 N/A 9.8 CRITICAL
** DISPUTED ** An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when the agent is restarted. NOTE: the vendor's perspective is "These are not vulnerabilities for us as we have provided the option to implement the authentication."
CVE-2023-33735 1 Dlink 2 Dir-846, Dir-846 Firmware 2025-01-10 N/A 9.8 CRITICAL
D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.
CVE-2024-43468 1 Microsoft 1 Configuration Manager 2025-01-10 N/A 9.8 CRITICAL
Microsoft Configuration Manager Remote Code Execution Vulnerability
CVE-2023-29747 1 Story Saver For Instagram - Video Downloader Project 1 Story Saver For Instagram - Video Downloader 2025-01-09 N/A 9.8 CRITICAL
Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is used, this can result in various attack consequences, such as ad display exceptions.
CVE-2018-11922 1 Qualcomm 44 215, 215 Firmware, Mdm9206 and 41 more 2025-01-09 N/A 9.8 CRITICAL
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.
CVE-2023-29722 1 Glitter Unicorn Wallpaper Project 1 Glitter Unicorn Wallpaper 2025-01-09 N/A 9.1 CRITICAL
The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack.
CVE-2024-29990 1 Microsoft 1 Azure Kubernetes Service Confidential Containers 2025-01-09 N/A 9.0 CRITICAL
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-38182 1 Microsoft 1 Dynamics 365 2025-01-08 N/A 9.0 CRITICAL
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
CVE-2023-45878 1 Gibbonedu 1 Gibbon 2025-01-08 N/A 9.8 CRITICAL
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path is used as the destination folder, concatenated with the absolute path of the installation directory. The content of the img parameter is base64 decoded and written to the defined file path. This allows creation of PHP files that permit Remote Code Execution (unauthenticated).
CVE-2023-43902 1 Emsigner 1 Emsigner 2025-01-08 N/A 9.8 CRITICAL
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
CVE-2023-2530 1 Puppet 1 Puppet Enterprise 2025-01-07 N/A 9.8 CRITICAL
A privilege escalation allowing remote code execution was discovered in the orchestration service.
CVE-2023-33604 1 Imperial Cms Project 1 Imperial Cms 2025-01-07 N/A 9.1 CRITICAL
Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp/ListSp.php. This vulnerability is exploited by attackers via a crafted POST request.
CVE-2023-38945 1 Multilaser 6 Re160, Re160 Firmware, Re160v and 3 more 2025-01-07 N/A 9.8 CRITICAL
Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows attackers to bypass the access control and gain complete access to the application via supplying a crafted URL.