Search Results (11529 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-2638 1 Rockwellautomation 2 Factorytalk Policy Manager, Factorytalk System Services 2025-01-02 5.9 Medium
Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local, authenticated non-admin user to craft a malicious backup archive, without password protection, that will be loaded by FactoryTalk System Services as a valid backup when a restore procedure takes places. User interaction is required for this vulnerability to be successfully exploited.
CVE-2023-0837 3 Apple, Microsoft, Teamviewer 3 Macos, Windows, Remote 2025-01-02 6.6 Medium
An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the options were locked. This can result in unwanted changes to the configuration.
CVE-2024-56317 2025-01-02 7.5 High
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based on user input. If input validation fails during decoding, the process stops, and no entries are restored by access-control-server.cpp, i.e., a denial of service.
CVE-2022-30150 1 Microsoft 12 Windows 10, Windows 10 1607, Windows 10 1809 and 9 more 2025-01-02 7.5 High
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
CVE-2024-22177 1 Openatom 1 Openharmony 2025-01-02 3.3 Low
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through get permission.
CVE-2024-13111 2025-01-02 5.6 Medium
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The manipulation leads to improper authentication. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVE-2024-13109 2025-01-02 5.3 Medium
A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-27937 1 Glpi-project 1 Glpi 2025-01-02 6.5 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched in version 10.0.13.
CVE-2024-27930 1 Glpi-project 1 Glpi 2025-01-02 6.5 Medium
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13.
CVE-2024-13110 2025-01-02 4.3 Medium
A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-21751 1 Microsoft 1 Azure Devops Server 2025-01-01 6.5 Medium
Azure DevOps Server Spoofing Vulnerability
CVE-2023-36004 1 Microsoft 22 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 19 more 2025-01-01 7.5 High
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
CVE-2023-36889 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-01-01 5.5 Medium
Windows Group Policy Security Feature Bypass Vulnerability
CVE-2023-33155 1 Microsoft 11 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 8 more 2025-01-01 7.8 High
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2023-32022 1 Microsoft 5 Windows Server 2012, Windows Server 2012 R2, Windows Server 2016 and 2 more 2025-01-01 7.6 High
Windows Server Service Security Feature Bypass Vulnerability
CVE-2023-32009 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2025-01-01 8.8 High
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
CVE-2023-21721 1 Microsoft 2 Onenote, Onenote For Android 2025-01-01 6.5 Medium
Microsoft OneNote Elevation of Privilege Vulnerability
CVE-2023-21817 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2025-01-01 7.8 High
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2023-21777 1 Microsoft 2 Azure App Service On Azure Stack, Azure Stack Hub 2025-01-01 8.7 High
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2023-21752 1 Microsoft 11 Windows 10, Windows 10 1507, Windows 10 1607 and 8 more 2025-01-01 7.1 High
Windows Backup Service Elevation of Privilege Vulnerability