Export limit exceeded: 363086 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (363086 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-32659 | 1 Subnet | 1 Powersystem Center | 2024-12-09 | 6.5 Medium |
| SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications. | ||||
| CVE-2024-8785 | 1 Progress | 1 Whatsup Gold | 2024-12-09 | 9.8 Critical |
| In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\. | ||||
| CVE-2023-34597 | 1 Fibaro | 2 Fgms-001, Fgms-001 Firmware | 2024-12-09 | 6.5 Medium |
| A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message. | ||||
| CVE-2024-7227 | 1 Avast | 1 Free Antivirus | 2024-12-09 | 7.8 High |
| Avast Free Antivirus AvastSvc Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22272. | ||||
| CVE-2024-7228 | 1 Avast | 1 Free Antivirus | 2024-12-09 | 5.5 Medium |
| Avast Free Antivirus Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Avast Free Antivirus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Service. By creating a symbolic link, an attacker can abuse the service to create a folder. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-22806. | ||||
| CVE-2024-7229 | 1 Avast | 2 Cleanup, Cleanup Premium | 2024-12-09 | 7.8 High |
| Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Cleanup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22892. | ||||
| CVE-2024-7230 | 1 Avast | 2 Cleanup, Cleanup Premium | 2024-12-09 | 7.8 High |
| Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Cleanup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22893. | ||||
| CVE-2024-7231 | 1 Avast | 2 Cleanup, Cleanup Premium | 2024-12-09 | 7.8 High |
| Avast Cleanup Premium Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Cleanup Premium. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Avast Cleanup Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22894. | ||||
| CVE-2024-27790 | 1 Claris | 1 Filemaker Server | 2024-12-09 | 7.5 High |
| Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests. | ||||
| CVE-2023-35885 | 1 Mgt-commerce | 1 Cloudpanel | 2024-12-09 | 9.8 Critical |
| CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | ||||
| CVE-2023-34600 | 1 Adiscon | 1 Loganalyzer | 2024-12-09 | 9.8 Critical |
| Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | ||||
| CVE-2023-2400 | 1 Devolutions | 1 Devolutions Server | 2024-12-09 | 2.7 Low |
| Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access. | ||||
| CVE-2024-4046 | 1 Huawei | 2 Emui, Harmonyos | 2024-12-09 | 6.4 Medium |
| Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability. | ||||
| CVE-2024-32998 | 1 Huawei | 2 Emui, Harmonyos | 2024-12-09 | 5.9 Medium |
| NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability. | ||||
| CVE-2024-12231 | 2 Codezips, Infoline-tr | 2 Project Management System, Project Management System | 2024-12-09 | 7.3 High |
| A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-32996 | 1 Huawei | 2 Emui, Harmonyos | 2024-12-09 | 6.2 Medium |
| Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability. | ||||
| CVE-2024-32997 | 1 Huawei | 2 Emui, Harmonyos | 2024-12-09 | 8.4 High |
| Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability. | ||||
| CVE-2024-32999 | 1 Huawei | 2 Emui, Harmonyos | 2024-12-09 | 6.8 Medium |
| Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability. | ||||
| CVE-2023-1862 | 1 Cloudflare | 1 Warp | 2024-12-09 | 7.3 High |
| Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IPC Named Pipe. This would have enabled an attacker to trigger WARP connect and disconnect commands, as well as obtaining network diagnostics and application configuration from the target's device. It is important to note that in order to exploit this, a set of requirements would need to be met, such as the target's device must've been reachable on port 445, allowed authentication with NULL sessions or otherwise having knowledge of the target's credentials. | ||||
| CVE-2023-52383 | 1 Huawei | 2 Emui, Harmonyos | 2024-12-09 | 4.7 Medium |
| Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability. | ||||