Vulnerabilities (CVE)

Filtered by CWE-284
Total 4322 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48912 1 Glpi-project 1 Glpi 2025-01-10 N/A 8.1 HIGH
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this issue.
CVE-2025-0213 1 Campcodes 1 Project Management System 2025-01-10 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Campcodes Project Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forms/update_forms.php?action=change_pic2&id=4. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-54096 1 Huawei 2 Emui, Harmonyos 2025-01-10 N/A 5.3 MEDIUM
Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.
CVE-2024-23360 1 Qualcomm 26 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 23 more 2025-01-09 N/A 8.4 HIGH
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
CVE-2016-10408 1 Qualcomm 10 9206 Lte Modem, 9206 Lte Modem Firmware, Apq8037 and 7 more 2025-01-09 N/A 8.4 HIGH
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
CVE-2024-29993 1 Microsoft 1 Azure Cyclecloud 2025-01-09 N/A 8.8 HIGH
Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2024-29990 1 Microsoft 1 Azure Kubernetes Service Confidential Containers 2025-01-09 N/A 9.0 CRITICAL
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-38163 1 Microsoft 4 Windows 10 21h2, Windows 10 22h2, Windows 11 21h2 and 1 more 2025-01-08 N/A 7.8 HIGH
Windows Update Stack Elevation of Privilege Vulnerability
CVE-2024-30059 1 Microsoft 1 Intune Mobile Application Management 2025-01-08 N/A 6.1 MEDIUM
Microsoft Intune for Android Mobile Application Management Tampering Vulnerability
CVE-2024-21424 1 Microsoft 1 Azure Compute Gallery 2025-01-08 N/A 6.5 MEDIUM
Azure Compute Gallery Elevation of Privilege Vulnerability
CVE-2024-26234 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-08 N/A 6.7 MEDIUM
Proxy Driver Spoofing Vulnerability
CVE-2024-28922 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-08 N/A 4.1 MEDIUM
Secure Boot Security Feature Bypass Vulnerability
CVE-2024-49068 1 Microsoft 1 Sharepoint Server 2025-01-08 N/A 8.2 HIGH
Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2024-43600 1 Microsoft 1 Office 2025-01-08 N/A 7.8 HIGH
Microsoft Office Elevation of Privilege Vulnerability
CVE-2024-43594 1 Microsoft 3 System Center 2019, System Center 2022, System Center 2025 2025-01-08 N/A 7.3 HIGH
Microsoft System Center Elevation of Privilege Vulnerability
CVE-2024-49107 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-08 N/A 7.3 HIGH
WmsRepair Service Elevation of Privilege Vulnerability
CVE-2024-28917 1 Microsoft 7 Azure Arc Extension Microsoft.azstackhci.operator, Azure Arc Extension Microsoft.azure.hybridnetwork, Azure Arc Extension Microsoft.azurekeyvaultsecretsprovider and 4 more 2025-01-07 N/A 6.2 MEDIUM
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
CVE-2024-37147 1 Glpi-project 1 Glpi 2025-01-07 N/A 4.3 MEDIUM
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.
CVE-2023-38946 1 Multilaser 2 Re160, Re160 Firmware 2025-01-07 N/A 8.8 HIGH
An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access to the application via supplying a crafted cookie.
CVE-2023-25174 1 Intel 1 Chipset Device Software 2025-01-07 N/A 6.7 MEDIUM
Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.