Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Data Record Ad HIGH 7.8
CVE-2024-1155

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enab…

Fix: 2024_q1+
Fix from $1,950 2024-02-20
Data Record Ad HIGH 7.8
CVE-2024-1156

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information an…

Fix: 2024_q1+
Fix from $1,950 2024-02-20
Digital Experience Platform MEDIUM 5.3
CVE-2024-25605

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 be…

Fix: 7.2 / 7.4.3.5+
Fix from $1,600 2024-02-20
Emui HIGH 7.5
CVE-2023-52379

Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.

Mitigation only
Fix from $1,950 2024-02-18
Emui HIGH 7.5
CVE-2023-52362

Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2024-02-18
Graalvm MEDIUM 5.9
CVE-2024-20921

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo…

Mitigation only
Fix from $1,600 2024-02-17
Android HIGH 7.8
CVE-2024-0034

In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to …

Patch available
Fix from $1,950 2024-02-16
Codeready Linux Builder HIGH 7.3
CVE-2024-1488

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runti…

Patch available
Fix from $1,950 2024-02-15
Lxd MEDIUM 6.7
CVE-2023-49721

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Fix: 5.21.0+
Fix from $1,600 2024-02-14
Assistive Context Aware Toolkit HIGH 7.8
CVE-2023-41231

Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable…

Fix: 2.0.0+
Fix from $1,950 2024-02-14
System Usage Report HIGH 7.8
CVE-2023-40154

Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable esca…

Fix: 2.0.1901+
Fix from $1,950 2024-02-14
Virtual Raid On Cpu HIGH 7.8
CVE-2023-34315

Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalati…

Fix: 8.0.8.1001+
Fix from $1,950 2024-02-14
Advisor MEDIUM 6.0
CVE-2023-29162

Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a…

Fix: 2021.8 / 2021.10+
Fix from $1,600 2024-02-14
Chipset Device Software HIGH 7.8
CVE-2023-28739

Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially …

Fix: 10.1.19444.8378+
Fix from $1,950 2024-02-14
Raidenftpd HIGH 7.3
CVE-2023-38960

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary…

No fix yet
Fix from $1,950 2024-02-13
Polarion Alm HIGH 7.8
CVE-2023-50236

A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissi…

Fix: 2404.0+
Fix from $1,950 2024-02-13
Pkg HIGH 7.8
CVE-2024-24828

pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On u…

Fix: after 5.8.1
Fix from $1,950 2024-02-09
Powerscale Onefs MEDIUM 5.5
CVE-2024-22430

Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user c…

Fix: 9.6.1+
Fix from $1,600 2024-02-01
Telerik Test Studio HIGH 7.8
CVE-2024-0833

In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer compon…

Fix: 2023.3.1330+
Fix from $1,950 2024-01-31
Storage Plug In HIGH 7.1
CVE-2024-21840

Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This …

Fix: 04.10.0+
Fix from $1,950 2024-01-30
Installshield MEDIUM 5.5
CVE-2023-29081

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authentica…

Mitigation only
Fix from $1,600 2024-01-26
Albo Pretorio Online HIGH 7.5
CVE-2024-22301

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On…

Fix: after 4.6.6
Fix from $1,950 2024-01-24
Ubuntu Pipewire Pulse MEDIUM 5.5
CVE-2022-4964

Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

Patch available
Fix from $1,600 2024-01-24
Iuclid HIGH 7.1
CVE-2024-0770

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function o…

No fix yet
Fix from $1,950 2024-01-21
Nuc P14e Laptop Element HIGH 7.8
CVE-2023-29244

Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software installers b…

Fix: 5.4.1.4479+
Fix from $1,950 2024-01-19
Datahub HIGH 8.8
CVE-2024-22409

DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user…

Fix: 0.12.1+
Fix from $1,950 2024-01-16
Emc Idrac Service Module HIGH 7.8
CVE-2024-22428

Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user…

Fix: after 5.2.0.0
Fix from $1,950 2024-01-16
Tuning Manager HIGH 7.1
CVE-2023-6457

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read…

Fix: 8.8.5-04+
Fix from $1,950 2024-01-16
Enterprise Linux MEDIUM 5.5
CVE-2024-23301

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to syst…

Fix: after 2.7
Fix from $1,600 2024-01-12
Automation Software Sysmac Studio HIGH 7.8
CVE-2022-45793

Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which wil…

Fix: after 1.54
Fix from $1,950 2024-01-10