Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Ipados HIGH 7.1
CVE-2024-40805

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchO…

Fix: 10.6 / 14.6+
Fix from $1,950 2024-07-29
macOS MEDIUM 5.5
CVE-2024-27888

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sonoma 14.4. An app may be a…

Fix: 14.4+
Fix from $1,600 2024-07-29
Streamer HIGH 7.8
CVE-2024-42053

The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user c…

Fix: 3.6.0.0+
Fix from $1,950 2024-07-28
Logging Operator HIGH 8.8
CVE-2024-36541

Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's …

Mitigation only
Fix from $1,950 2024-07-24
Systemlink MEDIUM 5.5
CVE-2024-6122

An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosu…

Fix: after 2024
Fix from $1,600 2024-07-22
Unclassified MEDIUM 6.1
CVE-2024-5321

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Aut…

Mitigation only
Fix from $1,600 2024-07-18
Peoplesoft Enterprise Hcm Shared Components MEDIUM 5.4
CVE-2024-21122

Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that…

Mitigation only
Fix from $1,600 2024-07-16
Factorytalk Policy Manager MEDIUM 5.5
CVE-2024-6326

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this…

Mitigation only
Fix from $1,600 2024-07-16
Factorytalk Policy Manager MEDIUM 6.5
CVE-2024-6325

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-ad…

Mitigation only
Fix from $1,600 2024-07-16
Unclassified HIGH 7.8
CVE-2024-32861

Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions.

Mitigation only
Fix from $1,950 2024-07-16
Internet Security MEDIUM 5.5
CVE-2024-3779

Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security prod…

Fix: 11.0.12012.0 / 11.0.15004.0+
Fix from $1,600 2024-07-16
Workspace HIGH 8.8
CVE-2024-6148

Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

Fix: 2404.1+
Fix from $1,950 2024-07-10
Android MEDIUM 5.5
CVE-2024-31312

In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposi…

Patch available
Fix from $1,600 2024-07-09
Zxcloud Irai HIGH 8.8
CVE-2024-22062

There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permis…

Fix: 7.23.40+
Fix from $1,950 2024-07-09
Unclassified HIGH 8.8
CVE-2024-3904

Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "…

Mitigation only
Fix from $1,950 2024-07-04
Ops Center Common Services MEDIUM 6.5
CVE-2024-2819

Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This…

Fix: 11.0.2-00+
Fix from $1,600 2024-07-02
Unclassified HIGH 7.8
CVE-2024-4679

Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi J…

Mitigation only
Fix from $1,950 2024-07-02
Security Access Manager MEDIUM 5.5
CVE-2024-35139

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incor…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-28
Router Manager MEDIUM 5.9
CVE-2024-39347

Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows m…

Fix: 1.2.5-8227 / 1.3.1-9346+
Fix from $1,600 2024-06-28
Security Access Manager MEDIUM 6.5
CVE-2023-38370

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious pa…

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
Pgadmin 4 MEDIUM 5.3
CVE-2024-6238

pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation dire…

Fix: 8.9+
Fix from $1,600 2024-06-25
Unclassified HIGH 7.7
CVE-2024-36495

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read …

Mitigation only
Fix from $1,950 2024-06-24
Langchain Experimental HIGH 7.8
CVE-2024-38459

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue …

Fix: 0.0.61+
Fix from $1,950 2024-06-16
Unclassified MEDIUM 6.7
CVE-2024-27180

An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.

No fix yet
Fix from $1,600 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27171

A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affecte…

Mitigation only
Fix from $1,950 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27166

Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/m…

No fix yet
Fix from $1,950 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27167

Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicio…

Mitigation only
Fix from $1,950 2024-06-14
Unclassified HIGH 7.7
CVE-2024-27155

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The progr…

Mitigation only
Fix from $1,950 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27150

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for th…

No fix yet
Fix from $1,950 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27151

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The progr…

No fix yet
Fix from $1,950 2024-06-14