Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Unclassified HIGH 7.8
CVE-2026-63425

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.8
CVE-2026-65940

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.5
CVE-2026-48790

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `s…

No fix yet
Fix from $4,000 2026-08-11
Powershell HIGH 7.3
CVE-2026-59119

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.2
CVE-2026-21074

Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.3
CVE-2026-4793

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and condu…

No fix yet
Fix from $1,950 2026-08-03
macOS HIGH 7.8
CVE-2026-39874

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A…

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
macOS HIGH 7.8
CVE-2026-39875

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A…

Fix: 14.8.8 / 15.7.8+
Fix from $1,950 2026-07-27
Unclassified HIGH 8.3
CVE-2026-17497

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the defa…

No fix yet
Fix from $1,950 2026-07-26
Unclassified HIGH 7.3
CVE-2026-16246

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16247

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %P…

No fix yet
Fix from $1,950 2026-07-20
Surrealdb MEDIUM 6.3
CVE-2024-58356

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE R…

Fix: 2.1.4+
Fix from $1,600 2026-07-18
Surrealdb HIGH 8.8
CVE-2023-54366

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables witho…

Fix: 1.0.1+
Fix from $1,950 2026-07-18
Secure Access HIGH 7.8
CVE-2026-40952

CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers wit…

Fix: 14.55+
Fix from $1,950 2026-07-15
Unclassified HIGH 8.5
CVE-2026-61828

Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixO…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.2
CVE-2026-53657

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver…

Patch available
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.4
CVE-2025-27462

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV dri…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-27463

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-27464

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified HIGH 7.8
CVE-2026-57895

Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folde…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.8
CVE-2026-57919

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ a…

Mitigation only
Fix from $1,950 2026-06-29
Youtrack MEDIUM 5.3
CVE-2026-57924

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Fix: 2026.2.16593+
Fix from $1,600 2026-06-26
Unclassified HIGH 8.1
CVE-2026-48725

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to requ…

Patch available
Fix from $1,950 2026-06-24
Nuxt MEDIUM 5.5
CVE-2026-56301

Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstr…

Fix: 3.21.7 / 4.4.7+
Fix from $1,600 2026-06-23
Unclassified HIGH 8.8
CVE-2026-12602

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permis…

Mitigation only
Fix from $1,950 2026-06-22
Unclassified MEDIUM 5.5
CVE-2026-53870

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversati…

Patch available
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.8
CVE-2025-15642

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to by…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified MEDIUM 6.7
CVE-2026-50255

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitr…

Mitigation only
Fix from $1,600 2026-06-16
Unclassified MEDIUM 5.5
CVE-2026-11931

Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local …

Mitigation only
Fix from $1,600 2026-06-15
Activemq HIGH 8.8
CVE-2026-49157

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The def…

Fix: 5.19.7 / 6.2.6+
Fix from $1,950 2026-06-01