Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Unclassified HIGH 7.4
CVE-2024-27152

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for th…

No fix yet
Fix from $1,950 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27153

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for th…

No fix yet
Fix from $1,950 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27148

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for th…

No fix yet
Fix from $1,950 2024-06-14
Unclassified HIGH 7.4
CVE-2024-27149

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for th…

No fix yet
Fix from $1,950 2024-06-14
Unclassified CRITICAL 9.8
CVE-2024-27144

The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure file…

Mitigation only
Fix from $2,300 2024-06-14
Sage Rtu Firmware HIGH 8.8
CVE-2024-37038

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perfo…

Patch available
Fix from $1,950 2024-06-12
Unclassified MEDIUM 5.9
CVE-2024-23847

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with Local…

Mitigation only
Fix from $1,600 2024-05-31
Unclassified MEDIUM 6.6
CVE-2024-32978

Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecure file permissions has been …

Mitigation only
Fix from $1,600 2024-05-27
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
Graphics Performance Analyzers HIGH 7.8
CVE-2023-43629

Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable es…

Fix: 2023.3+
Fix from $1,950 2024-05-16
Unclassified MEDIUM 6.7
CVE-2023-42433

Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potential…

Mitigation only
Fix from $1,600 2024-05-16
Unclassified MEDIUM 6.7
CVE-2023-42668

Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may …

Mitigation only
Fix from $1,600 2024-05-16
Graphics Performance Analyzers HIGH 7.8
CVE-2023-24460

Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable es…

Fix: 2023.3+
Fix from $1,950 2024-05-16
Human Resource Management System HIGH 8.8
CVE-2024-34221

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

No fix yet
Fix from $1,950 2024-05-14
Unclassified HIGH 7.3
CVE-2023-46870

extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 7.1
CVE-2024-4030

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary director…

Patch available
Fix from $1,950 2024-05-07
Unclassified HIGH 7.8
CVE-2024-34474

Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.

Mitigation only
Fix from $1,950 2024-05-05
Unclassified HIGH 7.5
CVE-2024-34455

Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2.

Patch available
Fix from $1,950 2024-05-03
Unclassified MEDIUM 6.8
CVE-2024-34011

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor…

Mitigation only
Fix from $1,600 2024-04-29
Siem MEDIUM 6.7
CVE-2022-48685

An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as r…

Fix: 7.1.2+
Fix from $1,600 2024-04-27
Brocade Sannav HIGH 7.2
CVE-2024-2859

By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote attack…

Fix: 2.3.0+
Fix from $1,950 2024-04-27
Registrationmagic HIGH 7.5
CVE-2023-23976

Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue…

Fix: 5.1.9.3+
Fix from $1,950 2024-04-24
Unclassified HIGH 7.1
CVE-2023-38291

An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various sof…

Mitigation only
Fix from $1,950 2024-04-22
Unclassified MEDIUM 6.1
CVE-2023-38294

Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autote…

Mitigation only
Fix from $1,600 2024-04-22
Unclassified HIGH 7.8
CVE-2023-38295

Certain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies on a missing permission that p…

Mitigation only
Fix from $1,950 2024-04-22
Unclassified HIGH 7.3
CVE-2024-32368

Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of ser…

Mitigation only
Fix from $1,950 2024-04-22
Brocade Sannav MEDIUM 6.0
CVE-2024-29967

In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, all…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Brocade Sannav MEDIUM 5.5
CVE-2024-29962

Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user …

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Vm Virtualbox HIGH 7.8
CVE-2024-21116

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.16+
Fix from $1,950 2024-04-16
Amplify Cli CRITICAL 9.8
CVE-2024-28056

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentica…

Fix: 12.10.1+
Fix from $2,300 2024-04-15