Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Cloudexplorer Lite HIGH 7.8
CVE-2023-50612

Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive …

No fix yet
Fix from $1,950 2024-01-06
Ubuntu Linux MEDIUM 6.4
CVE-2023-5536

A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their pr…

Fix: 24.04+
Fix from $1,600 2023-12-12
Privilege Management For Mac HIGH 8.8
CVE-2021-3187

An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running…

Fix: 5.7+
Fix from $1,950 2023-12-11
Secure Enterprise Client MEDIUM 6.5
CVE-2023-28870

Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-…

Fix: 12.22+
Fix from $1,600 2023-12-09
Emui CRITICAL 9.8
CVE-2023-46773

Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.

Mitigation only
Fix from $2,300 2023-12-06
Emui MEDIUM 5.3
CVE-2023-6273

Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to pe…

No fix yet
Fix from $1,600 2023-12-06
Opc HIGH 7.5
CVE-2023-37572

Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_…

Fix: 5.30+
Fix from $1,950 2023-12-05
Android MEDIUM 5.5
CVE-2023-40076

In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This …

Patch available
Fix from $1,600 2023-12-04
Android CRITICAL 9.8
CVE-2023-21216

In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local e…

Mitigation only
Fix from $2,300 2023-12-04
Gl Ax1800 Firmware CRITICAL 9.8
CVE-2023-47462

Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing funct…

Fix: after 3.125
Fix from $2,300 2023-11-29
Cszcms HIGH 7.2
CVE-2023-6302

A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templat…

No fix yet
Fix from $1,950 2023-11-27
Mprivacy Tools HIGH 8.8
CVE-2023-47250

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with…

Fix: 2.0.159 / 4.0.406g+
Fix from $1,950 2023-11-22
Openharmony MEDIUM 5.5
CVE-2023-42774

in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.

Fix: after 3.2.2
Fix from $1,600 2023-11-20
Openharmony HIGH 7.1
CVE-2023-3116

in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default per…

Fix: after 3.2.2
Fix from $1,950 2023-11-20
Infosphere Information Server MEDIUM 6.5
CVE-2023-40363

IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM…

Mitigation only
Fix from $1,600 2023-11-18
Concrete Cms CRITICAL 9.8
CVE-2023-48648

Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creatio…

Fix: 8.5.13 / 9.2.2+
Fix from $2,300 2023-11-17
Evo Nano Drone Firmware MEDIUM 6.5
CVE-2023-47335

Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fl…

Mitigation only
Fix from $1,600 2023-11-16
Secure Access Client HIGH 7.8
CVE-2023-41718

When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont…

No fix yet
Fix from $1,950 2023-11-15
Secure Access Client HIGH 7.8
CVE-2023-35080

A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulne…

Fix: 22.6+
Fix from $1,950 2023-11-15
Arc Rgb Controller HIGH 7.8
CVE-2023-32638

Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable esc…

Fix: 1.06+
Fix from $1,950 2023-11-14
Iris Xe Graphics HIGH 7.8
CVE-2023-27305

Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially ena…

Fix: 31.0.101.4255+
Fix from $1,950 2023-11-14
Debian Linux HIGH 7.8
CVE-2023-23583

Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable es…

Mitigation only
Fix from $1,950 2023-11-14
Emsigner CRITICAL 9.8
CVE-2023-43902

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registere…

No fix yet
Fix from $2,300 2023-11-14
Preload Directory HIGH 7.8
CVE-2023-4706

A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to…

Mitigation only
Fix from $1,950 2023-11-08
Advanced Export Products Orders Cron Csv Excel HIGH 7.5
CVE-2023-43984

Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_…

Fix: after 4.4.7
Fix from $1,950 2023-11-07
Avalanche HIGH 7.8
CVE-2023-41726

Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
Fedora MEDIUM 6.5
CVE-2023-4091

A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS modu…

Fix: 4.17.12 / 4.18.8+
Fix from $1,600 2023-11-03
Thinkpad 25 Firmware MEDIUM 6.7
CVE-2022-4575

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with phys…

Fix: 1.45 / 1.49+
Fix from $1,600 2023-10-30
Nessus Network Monitor HIGH 7.8
CVE-2023-5623

NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…

Fix: 6.3.0+
Fix from $1,950 2023-10-26
Wenwenai Cms HIGH 8.0
CVE-2023-45990

Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges.

No fix yet
Fix from $1,950 2023-10-25