CVE-2024-27710
https://notcve.org/view.php?id=CVE-2024-27710
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism. • https://blog.be-hacktive.com/eskooly-cve/eskooly-broken-authentication/cve-2024-27710-privilege-escalation-via-authentication-mechanism-in-eskooly-web-product-less-than-v3 • CWE-269: Improper Privilege Management •
CVE-2024-27715
https://notcve.org/view.php?id=CVE-2024-27715
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism. • https://blog.be-hacktive.com/eskooly-cve/cve-2024-27715-inadequate-password-update-verification-in-eskooly-web-product-less-than-v3.0 • CWE-620: Unverified Password Change •
CVE-2024-39934
https://notcve.org/view.php?id=CVE-2024-39934
Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment. • https://checkmk.com/werk/16434 https://github.com/elabit/robotmk/commit/78c1174ab2df43813050d0c22e1efb8636f8715e https://github.com/elabit/robotmk/compare/v2.0.0...v2.0.1 https://github.com/elabit/robotmk/releases/tag/v2.0.1 • CWE-284: Improper Access Control •
CVE-2024-37726
https://notcve.org/view.php?id=CVE-2024-37726
., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe • https://github.com/carsonchan12345/CVE-2024-37726-MSI-Center-Local-Privilege-Escalation https://github.com/NextGenPentesters/CVE-2024-37726-MSI-Center-Local-Privilege-Escalation • CWE-269: Improper Privilege Management •
CVE-2024-25088
https://notcve.org/view.php?id=CVE-2024-25088
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code. • https://jungo.com/windriver/versions https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-04 https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-001_en.pdf • CWE-269: Improper Privilege Management •