Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Wazuh HIGH 7.5
CVE-2025-15615

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiatio…

Fix: 4.8.0+
Fix from $1,950 2026-03-27
Wazuh HIGH 7.5
CVE-2026-32983

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiatio…

Fix: after 4.7.3
Fix from $1,950 2026-03-27
Unclassified HIGH 7.8
CVE-2026-32680

The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to s…

Mitigation only
Fix from $1,950 2026-03-26
Unclassified HIGH 8.2
CVE-2026-24063

When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script …

Mitigation only
Fix from $1,950 2026-03-18
Unclassified MEDIUM 6.2
CVE-2016-20029

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used…

No fix yet
Fix from $1,600 2026-03-16
Openshift Data Foundation MEDIUM 6.4
CVE-2025-8766

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-03-13
Fuse MEDIUM 6.4
CVE-2025-57849

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable …

Mitigation only
Fix from $1,600 2026-03-13
Visionline HIGH 7.8
CVE-2026-3315

Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA…

Fix: 1.34.0+
Fix from $1,950 2026-03-10
.net HIGH 7.8
CVE-2026-26131

Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

Fix: 10.0.4+
Fix from $1,950 2026-03-10
Unclassified MEDIUM 5.5
CVE-2026-28267

Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system direct…

Mitigation only
Fix from $1,600 2026-03-10
Agent HIGH 7.8
CVE-2026-28727

Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before buil…

Fix: 17.0.41186+
Fix from $1,950 2026-03-06
Cyber Protect MEDIUM 5.0
CVE-2026-28717

Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before buil…

Fix: 17.0.41186+
Fix from $1,600 2026-03-06
Ups Multi Ups Management Console HIGH 7.8
CVE-2026-26034

UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an att…

Mitigation only
Fix from $1,950 2026-03-05
Powerscale Onefs MEDIUM 6.7
CVE-2026-21423

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A …

Fix: 9.10.1.6 / 9.13.0.0+
Fix from $1,600 2026-03-04
System Event Utility HIGH 7.1
CVE-2026-2915

HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated…

Fix: 3.2.16+
Fix from $1,950 2026-03-03
Securebrowser For Onegate MEDIUM 6.7
CVE-2026-27653

The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary …

Fix: 1.4.8 / 2.0.15+
Fix from $1,600 2026-02-27
Unclassified HIGH 7.8
CVE-2026-23703

The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user ma…

Mitigation only
Fix from $1,950 2026-02-26
Genetec Update Service HIGH 7.8
CVE-2025-1789

Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevate…

Fix: 2.10.6+
Fix from $1,950 2026-02-24
Nessus Agent MEDIUM 6.1
CVE-2026-2026

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, poten…

Fix: 11.0.4 / 11.1.2+
Fix from $1,600 2026-02-13
Unclassified MEDIUM 6.7
CVE-2025-36511

Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an escalation…

Mitigation only
Fix from $1,600 2026-02-10
Unclassified MEDIUM 6.7
CVE-2025-36522

Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications may allow …

Mitigation only
Fix from $1,600 2026-02-10
Graphics Driver MEDIUM 6.7
CVE-2025-32453

Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unpr…

Fix: 6.12.28-linux-250521T070434Z / 25.30.1702.0+
Fix from $1,600 2026-02-10
Unclassified MEDIUM 6.7
CVE-2025-31655

Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. U…

Mitigation only
Fix from $1,600 2026-02-10
Unclassified MEDIUM 6.7
CVE-2025-22849

Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_M…

Mitigation only
Fix from $1,600 2026-02-10
Unclassified HIGH 7.8
CVE-2026-25931

vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats t…

Patch available
Fix from $1,950 2026-02-09
Unclassified MEDIUM 6.2
CVE-2020-37160

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows syste…

No fix yet
Fix from $1,600 2026-02-07
Discover MEDIUM 6.5
CVE-2025-15339

Tanium addressed an incorrect default permissions vulnerability in Discover.

Fix: 4.10.118+
Fix from $1,600 2026-02-05
Comply MEDIUM 6.5
CVE-2025-15340

Tanium addressed an incorrect default permissions vulnerability in Comply.

Fix: 2.24.159 / 2.29.124+
Fix from $1,600 2026-02-05
Benchmark MEDIUM 6.5
CVE-2025-15341

Tanium addressed an incorrect default permissions vulnerability in Benchmark.

Fix: 2.7.98 / 2.9.188+
Fix from $1,600 2026-02-05
Enforce MEDIUM 6.5
CVE-2025-15343

Tanium addressed an incorrect default permissions vulnerability in Enforce.

Fix: 2.7.367 / 2.8.601+
Fix from $1,600 2026-02-05