7.8

CVSS3.1

CVE-2024-9062 - macOS Archify: Local Privilege Escalation

The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. Archify follows the "factored applications" model, delegating privileged operations—such as arbitrary…

📅 Published: June 10, 2025, 11:25 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS3.1

CVE-2025-1055 - K7 Security Anti-Malware: IOCTL in K7RKScan.sys Allows Arbitrary Termination of High-Privilege and …

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by…

📅 Published: June 10, 2025, 11:23 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-8270 - macOS Rocket.Chat: TCC Policy Bypass via Dylib Injection Due to Missing Code Signing Flags and Dang…

The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling the exploitation or abuse of permissions specified in its entitlements (e.g., microphone, camera, automation, network client). Since Rocket.Chat was no…

📅 Published: June 10, 2025, 11:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-7457 - macOS Stash network-management utility: Unauthorized Manipulation of System Network Preferences

The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the client's authorization reference, the helper invokes AuthorizationCopyRights() using its own privileged context (root), effectively authorizing itsel…

📅 Published: June 10, 2025, 11:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2025-32717 - Microsoft Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

📅 Published: June 10, 2025, 11:15 p.m. 🔄 Last Modified: Feb. 20, 2026, 4 p.m.

4.7

CVSS3.1

CVE-2025-30675 - Apache CloudStack: Unauthorised template/ISO list access to the domain/resource admins

In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue by intentionally specifying the 'domainid' parameter along with the 'filter=self' or 'filter=selfexecutable' values. This allows the attacker…

📅 Published: June 10, 2025, 11:12 p.m. 🔄 Last Modified: July 1, 2025, 8:14 p.m.

2.3

CVSS4.0

CVE-2025-22829 - Apache CloudStack: Unauthorised access to dedicated resources in Quota plugin

The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disable reception of quota-related emails for an…

📅 Published: June 10, 2025, 11:11 p.m. 🔄 Last Modified: June 25, 2025, 7:38 p.m.

8.1

CVSS3.1

CVE-2025-26521 - Apache CloudStack: CKS cluster in project exposes user API keys

When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create the secret config in the CKS-based Kubernetes cluster. A member of the project who can access the CKS-based Kub…

📅 Published: June 10, 2025, 11:08 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS3.1

CVE-2025-47849 - Apache CloudStack: Insecure access of user's API/Secret Keys in the same domain

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation is not appropriately restricted and al…

📅 Published: June 10, 2025, 11:07 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.

8.8

CVSS3.1

CVE-2025-47713 - Apache CloudStack: Domain Admin can reset Admin password in Root Domain

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricted and allows the attacker to assume con…

📅 Published: June 10, 2025, 11:06 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.
Total resulsts: 348200
Page 4957 of 34,820
« previous page » next page
Filters