Page 6 of 3630 results (0.015 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Jan 2025 — This vulnerability allows local attackers to escalate privileges on affected installations of SonicWALL NSv. ... An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. • https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003 • CWE-269: Improper Privilege Management •

CVSS: 7.8EPSS: 0%CPEs: -EXPL: 0

09 Jan 2025 — This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. ... An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. •

CVSS: 6.8EPSS: 0%CPEs: -EXPL: 0

09 Jan 2025 — Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field • https://support.neat.no/article/devices-running-microsoft-teams-allow-for-buffer-overflow-vulnerability • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

07 Jan 2025 — Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. • https://www.dell.com/support/kbdoc/en-us/000269079/dsa-2025-034-security-update-for-dell-update-package-dup-framework-vulnerability • CWE-280: Improper Handling of Insufficient Permissions or Privileges •

CVSS: 6.1EPSS: 0%CPEs: -EXPL: 0

07 Jan 2025 — Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html. • http://adportal.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.6EPSS: 0%CPEs: 10EXPL: 0

03 Jan 2025 — This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk. • https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo • CWE-656: Reliance on Security Through Obscurity •

CVSS: 9.8EPSS: 0%CPEs: -EXPL: 0

03 Jan 2025 — An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component. • https://github.com/CV1523/CVEs/blob/main/CVE-2024-55507.md • CWE-281: Improper Preservation of Permissions •

CVSS: 4.4EPSS: 0%CPEs: 2EXPL: 0

02 Jan 2025 — Local privilege escalation due to excessive permissions assigned to Tray Monitor service. • https://security-advisory.acronis.com/advisories/SEC-5342 • CWE-266: Incorrect Privilege Assignment •

CVSS: 6.6EPSS: 0%CPEs: 1EXPL: 0

02 Jan 2025 — Local privilege escalation due to DLL hijacking vulnerability. • https://security-advisory.acronis.com/advisories/SEC-2245 • CWE-427: Uncontrolled Search Path Element •

CVSS: 7.3EPSS: 0%CPEs: 1EXPL: 0

02 Jan 2025 — Local privilege escalation due to DLL hijacking vulnerability. • https://security-advisory.acronis.com/advisories/SEC-6418 • CWE-427: Uncontrolled Search Path Element •