Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Juju MEDIUM 6.5
CVE-2024-8037

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to t…

Fix: 2.9.51 / 3.1.10+
Fix from $1,600 2024-10-02
Tomcat Connectors MEDIUM 5.9
CVE-2024-46544

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configu…

Fix: 1.2.50+
Fix from $1,600 2024-09-23
Mautic MEDIUM 6.5
CVE-2022-25776

Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Us…

Fix: 4.4.12 / 5.0.4+
Fix from $1,600 2024-09-18
macOS MEDIUM 5.5
CVE-2024-44135

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. An app may be able to acc…

Fix: 14.7+
Fix from $1,600 2024-09-17
macOS MEDIUM 5.5
CVE-2024-44151

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An ap…

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
Vaultwarden HIGH 8.8
CVE-2024-39924EPSS 13%

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization pr…

Mitigation only
Fix from $1,950 2024-09-13
2800c Optixpanel Compact Firmware HIGH 8.8
CVE-2024-8533

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permi…

Fix: 4.0.2.106 / 4.0.2.116+
Fix from $1,950 2024-09-12
Edge MEDIUM 6.5
CVE-2024-38222

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Fix: 128.0.2739.42+
Fix from $1,600 2024-09-12
Android HIGH 7.8
CVE-2024-40654

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit…

Patch available
Fix from $1,950 2024-09-11
Android HIGH 7.8
CVE-2024-40655

In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background d…

Patch available
Fix from $1,950 2024-09-11
Android MEDIUM 5.5
CVE-2024-34648

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

Mitigation only
Fix from $1,600 2024-09-04
Snap Deploy MEDIUM 5.5
CVE-2024-34018

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build …

Fix: 6+
Fix from $1,600 2024-08-29
Enterprise Management System HIGH 7.5
CVE-2024-44760

Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attacke…

Fix: after 18.8
Fix from $1,950 2024-08-28
Unclassified HIGH 7.1
CVE-2023-45896

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distr…

Patch available
Fix from $1,950 2024-08-28
Request Store HIGH 7.8
CVE-2024-43791

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that the…

Mitigation only
Fix from $1,950 2024-08-23
Unclassified HIGH 7.8
CVE-2024-4763

An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could …

Mitigation only
Fix from $1,950 2024-08-16
Unclassified HIGH 7.8
CVE-2024-2175

An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that c…

Mitigation only
Fix from $1,950 2024-08-16
Xxl Job HIGH 8.8
CVE-2024-42681

Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.

No fix yet
Fix from $1,950 2024-08-15
Memory And Storage Tool Gui MEDIUM 5.5
CVE-2024-27461

Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service vi…

Fix: 2.5.0+
Fix from $1,600 2024-08-14
Advisor HIGH 7.8
CVE-2024-26025

Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalati…

Fix: 2024.1+
Fix from $1,950 2024-08-14
Unclassified MEDIUM 6.7
CVE-2024-23974

Incorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially enable escalation of privilege …

Mitigation only
Fix from $1,600 2024-08-14
Distribution For Gdb HIGH 7.8
CVE-2024-23495

Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially e…

Fix: 2024.0.1 / 2024.1+
Fix from $1,950 2024-08-14
Unclassified MEDIUM 6.7
CVE-2024-22378

Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authe…

Mitigation only
Fix from $1,600 2024-08-14
Unclassified MEDIUM 6.7
CVE-2023-43747

Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user…

Mitigation only
Fix from $1,600 2024-08-14
Uprof HIGH 7.8
CVE-2023-31349

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting …

Fix: 4.1.424 / 4.2.816+
Fix from $1,950 2024-08-13
Unclassified MEDIUM 6.3
CVE-2024-6640

In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Requests, a crafted Echo Request pa…

Mitigation only
Fix from $1,600 2024-08-12
Android MEDIUM 5.5
CVE-2024-34616

Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

Mitigation only
Fix from $1,600 2024-08-07
Firefox HIGH 8.1
CVE-2024-7525

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of r…

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Teamcity HIGH 7.8
CVE-2024-43114

In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

Fix: 2024.07.1+
Fix from $1,950 2024-08-06
Cato Client HIGH 7.8
CVE-2024-6974

Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

Fix: 5.10.34+
Fix from $1,950 2024-07-31