| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. |
| Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally. |
| Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
| vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. |
| Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. |
| Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
| Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
| Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. |
| Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. |
| WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials. |
| WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a valid administrator email address, and a valid nonce to obtain session cookies and authenticate as that user. |
| Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attackers can exploit improper authentication handling to obtain the authentication status and privileges of a previously authenticated user without providing valid credentials. |
| The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation. |
| Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only. |
| Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. |