Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Amplify Cli CRITICAL 9.8
CVE-2024-28056

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentica…

Fix: 12.10.1+
Fix from $2,300 2024-04-15
Junos MEDIUM 5.0
CVE-2024-21615

An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access co…

Fix: 21.2+
Fix from $1,600 2024-04-12
Roblox Purchasing Hub HIGH 8.8
CVE-2024-31442

Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users…

Fix: 1.0.2+
Fix from $1,950 2024-04-08
Filmora HIGH 7.8
CVE-2024-26574

Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSN…

Mitigation only
Fix from $1,950 2024-04-08
Emui HIGH 7.5
CVE-2023-52545

Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,950 2024-04-08
Emui MEDIUM 5.3
CVE-2023-52717

Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,600 2024-04-07
Emui CRITICAL 9.1
CVE-2024-30415

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect avail…

No fix yet
Fix from $2,300 2024-04-07
Unclassified HIGH 7.8
CVE-2024-30977

An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password compo…

No fix yet
Fix from $1,950 2024-04-05
Macro Expert HIGH 7.8
CVE-2024-27674

Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an unprivilege…

Fix: after 4.9.4
Fix from $1,950 2024-04-03
Robot Schedule HIGH 7.3
CVE-2024-0259

Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrit…

Fix: 3.04+
Fix from $1,950 2024-03-28
Grab HIGH 7.8
CVE-2024-25958

Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker …

Fix: 5.0.5+
Fix from $1,950 2024-03-26
G5dfr Firmware MEDIUM 6.2
CVE-2024-22085

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.

Fix: 1.2.1.12+
Fix from $1,600 2024-03-20
Unified Management Platform MEDIUM 5.5
CVE-2024-25654

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP applic…

No fix yet
Fix from $1,600 2024-03-18
Control M HIGH 7.8
CVE-2024-1605

BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissi…

Fix: 9.0.20.238 / 9.0.21.201+
Fix from $1,950 2024-03-18
Rotp MEDIUM 5.5
CVE-2024-28862

The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly pe…

Fix: 6.3.0+
Fix from $1,600 2024-03-16
Unclassified MEDIUM 6.7
CVE-2023-28389

Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enabl…

Mitigation only
Fix from $1,600 2024-03-14
Windows Defender Antimalware Platform MEDIUM 5.5
CVE-2024-20671

Microsoft Defender Security Feature Bypass Vulnerability

Fix: 4.18.24010.12+
Fix from $1,600 2024-03-12
Visionos MEDIUM 5.5
CVE-2024-23295

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be a…

Fix: 1.1+
Fix from $1,600 2024-03-08
Ipados MEDIUM 5.5
CVE-2024-23201

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma …

Fix: 10.3 / 12.7.4+
Fix from $1,600 2024-03-08
Plone HIGH 7.5
CVE-2024-22889

Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted req…

Mitigation only
Fix from $1,950 2024-03-06
Account MEDIUM 5.5
CVE-2024-20841

Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

Fix: 14.8.00.3+
Fix from $1,600 2024-03-05
Android MEDIUM 5.3
CVE-2024-20830

Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.

Mitigation only
Fix from $1,600 2024-03-05
Android HIGH 8.2
CVE-2024-20005

In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,950 2024-03-04
Couchbase Server HIGH 7.5
CVE-2023-49338

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of lo…

Fix: 7.2.4+
Fix from $1,950 2024-02-28
Cyber Protect MEDIUM 5.5
CVE-2023-48678

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) b…

Fix: 16+
Fix from $1,600 2024-02-27
Advanced Dashboard HIGH 8.4
CVE-2023-50975

The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeE…

Fix: after 3.0.3
Fix from $1,950 2024-02-21
Openvpn Gui HIGH 8.4
CVE-2023-7235

The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries w…

Fix: 2.6.9+
Fix from $1,950 2024-02-21
macOS MEDIUM 5.5
CVE-2023-42945

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Blue…

Mitigation only
Fix from $1,600 2024-02-21
Ipad Os MEDIUM 5.5
CVE-2023-42953

A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadO…

Fix: 10.1 / 17.1+
Fix from $1,600 2024-02-21
Ipad Os HIGH 7.8
CVE-2023-42928

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able to gain elevated privileges.

Fix: 17.1+
Fix from $1,950 2024-02-21