Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Unclassified HIGH 8.5
CVE-2026-33590

Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution.…

Patch available
Fix from $1,950 2026-05-28
Multipass HIGH 7.8
CVE-2026-49237

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version…

Fix: 1.16.3+
Fix from $1,950 2026-05-28
Development System HIGH 7.0
CVE-2026-44469

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A lo…

Fix: 3.5.22.20+
Fix from $1,950 2026-05-26
Development System HIGH 7.8
CVE-2026-44468

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local att…

Fix: 3.5.22.20+
Fix from $1,950 2026-05-26
Unclassified HIGH 8.4
CVE-2018-25359

Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by …

No fix yet
Fix from $1,950 2026-05-25
Powerflex Appliance Intelligent Catalog HIGH 7.5
CVE-2025-32749

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacke…

Fix: 3.7.8.0 / 48.383.00+
Fix from $1,950 2026-05-22
Moveit Automation HIGH 7.5
CVE-2026-8487

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEi…

Fix: 2025.0.11 / 2025.1.7+
Fix from $1,950 2026-05-20
Unclassified HIGH 8.1
CVE-2026-47107

Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted wi…

Patch available
Fix from $1,950 2026-05-19
Unclassified MEDIUM 6.9
CVE-2025-48516

Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse th…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified HIGH 8.5
CVE-2026-0432

Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation result…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified HIGH 7.0
CVE-2025-48512

Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to ach…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified MEDIUM 6.8
CVE-2026-36742

Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode).

Mitigation only
Fix from $1,600 2026-05-13
Android MEDIUM 5.5
CVE-2026-21015

Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.

Mitigation only
Fix from $1,600 2026-05-13
Unclassified MEDIUM 5.4
CVE-2026-20718

Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring 3: User Applications may allo…

Mitigation only
Fix from $1,600 2026-05-12
Spring Ai HIGH 7.5
CVE-2026-41712

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure betw…

Fix: 1.0.7 / 1.1.6+
Fix from $1,950 2026-05-12
Unclassified HIGH 7.8
CVE-2026-45393

A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 8.5
CVE-2026-0539

Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting…

Mitigation only
Fix from $1,950 2026-04-22
Openharness HIGH 8.2
CVE-2026-6823

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["…

Fix: 0.1.7+
Fix from $1,950 2026-04-21
Openharness HIGH 8.8
CVE-2026-6819

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /rel…

Fix: 0.1.7+
Fix from $1,950 2026-04-21
Skymec It Manager HIGH 7.8
CVE-2026-39454

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A …

Fix: after 2024.005.10a
Fix from $1,950 2026-04-20
Pandora Fms MEDIUM 6.5
CVE-2026-30811

Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 thr…

Fix: 800.1+
Fix from $1,600 2026-04-13
Galaxy Wearable MEDIUM 5.5
CVE-2026-21013

Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.

Fix: 2.2.68.26+
Fix from $1,600 2026-04-13
Unclassified HIGH 7.8
CVE-2026-25203

Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than …

Mitigation only
Fix from $1,950 2026-04-10
Web Terminal MEDIUM 6.4
CVE-2025-57853

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-w…

Mitigation only
Fix from $1,600 2026-04-08
Openshift Update Service MEDIUM 6.4
CVE-2025-57854

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-04-08
Process Automation Manager MEDIUM 6.4
CVE-2025-58713

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Ansible Automation Platform MEDIUM 6.4
CVE-2025-57847

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being crea…

Fix: after 2.6
Fix from $1,600 2026-04-08
Advanced Cluster Management For Kubernetes MEDIUM 6.7
CVE-2025-57851

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Tetra Connectivity Server HIGH 7.3
CVE-2025-7024

Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may ex…

Mitigation only
Fix from $1,950 2026-04-03
Bigfix Platform HIGH 7.8
CVE-2026-21765

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host mach…

Fix: after 11.0.5
Fix from $1,950 2026-04-02