Vulnerabilities (CVE)

Filtered by CWE-276
Total 1559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-6238 1 Pgadmin 1 Pgadmin 4 2026-06-17 N/A 7.4 HIGH
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.
CVE-2024-6148 1 Citrix 1 Workspace 2026-06-17 N/A 8.8 HIGH
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
CVE-2024-6122 1 Ni 2 Flexlogger, Systemlink 2026-06-17 N/A 5.5 MEDIUM
An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service.
CVE-2024-5967 2026-06-17 N/A 2.7 LOW
A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL  independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with admin access (permission manage-realm) to change the LDAP host URL ("Connection URL") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console or compromised a user with sufficient privileges can leak domain credentials and attack the domain.
CVE-2024-5474 1 Lenovo 1 Dolby Vision Provisioning 2026-06-17 N/A 5.5 MEDIUM
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by this issue.
CVE-2024-5321 2026-06-17 N/A 6.1 MEDIUM
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
CVE-2024-58050 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-58049 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.0 MEDIUM
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-58047 1 Huawei 1 Harmonyos 2026-06-17 N/A 5.0 MEDIUM
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-58046 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-58044 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 8.4 HIGH
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2024-57684 1 Dlink 2 Dir-816, Dir-816 Firmware 2026-06-17 N/A 9.8 CRITICAL
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.
CVE-2024-57604 1 Mayswind 1 Ezbookkeeping 2026-06-17 N/A 9.8 CRITICAL
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
CVE-2024-57548 1 Cmsimple 1 Cmsimple 2026-06-17 N/A 9.1 CRITICAL
CMSimple 5.16 allows the user to edit log.php file via print page.
CVE-2024-56525 2026-06-17 N/A 9.8 CRITICAL
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
CVE-2024-56447 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 7.8 HIGH
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-56440 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
CVE-2024-55959 2026-06-17 N/A 9.1 CRITICAL
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
CVE-2024-55957 2026-06-17 N/A 7.8 HIGH
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems.
CVE-2024-55950 2026-06-17 N/A N/A
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential security vulnerabilities. The application currently holds powerful permissions including camera, microphone access, and the ability to access personal folders (Downloads, Documents, etc.) through Apple Events, while also maintaining dangerous entitlements that enable code injection. The concerning entitlements are com.apple.security.cs.allow-dyld-environment-variables and com.apple.security.cs.disable-library-validation. Since Tabby's plugins and themes are NodeJS-based without native libraries or frameworks, and no environment variables are used in the codebase, it is recommended to review and remove at least one of the entitlements (com.apple.security.cs.disable-library-validation or com.apple.security.cs.allow-dyld-environment-variables) to prevent DYLD_INSERT_LIBRARIES injection while maintaining full application functionality. This vulnerability is fixed in 1.0.216.