Total
1337 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-47040 | 1 Askey | 2 Rtf3505vw-n1, Rtf3505vw-n1 Firmware | 2025-04-02 | N/A | 7.8 HIGH |
An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after placing a crafted file in the /tmp directory and sending crafted packets through port 80. | |||||
CVE-2022-20456 | 1 Google | 1 Android | 2025-04-02 | N/A | 7.8 HIGH |
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703780 | |||||
CVE-2025-24207 | 2025-04-01 | N/A | 9.8 CRITICAL | ||
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to enable iCloud storage features without user consent. | |||||
CVE-2025-2782 | 2025-04-01 | N/A | N/A | ||
The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Terminal Services Agent: from 12.0 through 12.10. | |||||
CVE-2025-2781 | 2025-04-01 | N/A | N/A | ||
The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Mobile VPN with SSL Client: from 11.0 through 12.11. | |||||
CVE-2025-24195 | 2025-04-01 | N/A | 9.8 CRITICAL | ||
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges. | |||||
CVE-2024-53351 | 1 Linuxfoundation | 1 Pipecd | 2025-04-01 | N/A | 9.8 CRITICAL |
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges. | |||||
CVE-2023-46270 | 2025-03-28 | N/A | 3.3 LOW | ||
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items. | |||||
CVE-2024-26574 | 1 Wondershare | 1 Filmora | 2025-03-28 | N/A | 7.8 HIGH |
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe | |||||
CVE-2025-25535 | 2025-03-27 | N/A | 9.8 CRITICAL | ||
HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request. | |||||
CVE-2022-23454 | 2025-03-27 | N/A | 7.8 HIGH | ||
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |||||
CVE-2022-23453 | 2025-03-27 | N/A | 7.8 HIGH | ||
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |||||
CVE-2024-26302 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2025-03-27 | N/A | 4.8 MEDIUM |
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager. | |||||
CVE-2024-6148 | 1 Citrix | 1 Workspace | 2025-03-25 | N/A | 8.8 HIGH |
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5 | |||||
CVE-2025-24135 | 1 Apple | 1 Macos | 2025-03-25 | N/A | 7.8 HIGH |
This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges. | |||||
CVE-2024-54564 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2025-03-25 | N/A | 6.5 MEDIUM |
This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied. | |||||
CVE-2025-24176 | 1 Apple | 1 Macos | 2025-03-24 | N/A | 7.1 HIGH |
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local attacker may be able to elevate their privileges. | |||||
CVE-2025-24093 | 1 Apple | 1 Macos | 2025-03-24 | N/A | 9.8 CRITICAL |
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3. An app may be able to access removable volumes without user consent. | |||||
CVE-2024-51440 | 2025-03-22 | N/A | 7.8 HIGH | ||
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component. | |||||
CVE-2023-1809 | 1 W3eden | 1 Download Manager | 2025-03-21 | N/A | 7.5 HIGH |
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files. |