Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Performance MEDIUM 6.5
CVE-2025-15336

Tanium addressed an incorrect default permissions vulnerability in Performance.

Fix: 1.17.134 / 1.21.141+
Fix from $1,600 2026-02-05
Patch MEDIUM 6.5
CVE-2025-15337

Tanium addressed an incorrect default permissions vulnerability in Patch.

Fix: 3.17.2300 / 3.19.232+
Fix from $1,600 2026-02-05
Partner Integration MEDIUM 6.5
CVE-2025-15338

Tanium addressed an incorrect default permissions vulnerability in Partner Integration.

Fix: 1.0.224 / 1.2.33+
Fix from $1,600 2026-02-05
Unclassified CRITICAL 9.8
CVE-2020-37129

Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Atta…

Mitigation only
Fix from $2,300 2026-02-05
Unclassified HIGH 8.8
CVE-2025-10314

Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attac…

Mitigation only
Fix from $1,950 2026-02-05
Superduper\! HIGH 7.8
CVE-2025-69604

An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package th…

Fix: 3.12+
Fix from $1,950 2026-01-29
Autogpt Platform HIGH 8.8
CVE-2026-24780

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.44+
Fix from $1,950 2026-01-29
Icinga MEDIUM 5.5
CVE-2026-24413

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not s…

Fix: 2.13.14 / 2.14.8+
Fix from $1,600 2026-01-29
Icinga Powershell Framework MEDIUM 5.5
CVE-2026-24414

The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versi…

Fix: 1.11.2 / 1.12.4+
Fix from $1,600 2026-01-29
Unclassified HIGH 7.0
CVE-2025-13905

CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more execut…

Mitigation only
Fix from $1,950 2026-01-29
Unclassified MEDIUM 6.7
CVE-2026-0705

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.4.…

Mitigation only
Fix from $1,600 2026-01-27
Builder HIGH 7.1
CVE-2025-67230

Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke ex…

Fix: 0.33.0+
Fix from $1,950 2026-01-23
Unclassified HIGH 8.8
CVE-2021-47852

Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable wit…

No fix yet
Fix from $1,950 2026-01-21
Node.js MEDIUM 5.3
CVE-2025-55132

A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only …

Fix: 20.20.0 / 22.22.0+
Fix from $1,600 2026-01-20
Unclassified HIGH 7.8
CVE-2021-47761

MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB…

No fix yet
Fix from $1,950 2026-01-15
Kace Desktop Authority MEDIUM 5.3
CVE-2025-67813

Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication

Fix: 11.3.2+
Fix from $1,600 2026-01-12
Mc102 G Firmware CRITICAL 9.8
CVE-2025-60262

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability …

Mitigation only
Fix from $2,300 2026-01-06
Arduino Ide HIGH 7.3
CVE-2025-64724

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions…

Fix: 2.3.7+
Fix from $1,950 2025-12-18
Dell Color Management HIGH 7.8
CVE-2025-53398

The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,

Fix: after 3.3.008
Fix from $1,950 2025-12-17
Dell Color Management HIGH 7.8
CVE-2025-53919

An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak…

Fix: after 3.3.008
Fix from $1,950 2025-12-17
macOS MEDIUM 5.5
CVE-2025-43519

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. A…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
Unclassified HIGH 7.8
CVE-2025-13155

An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated…

Mitigation only
Fix from $1,950 2025-12-10
Recursor HIGH 7.5
CVE-2025-59030

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

Fix: 5.1.9 / 5.2.7+
Fix from $1,950 2025-12-09
Unclassified MEDIUM 6.4
CVE-2025-57850

A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with…

Mitigation only
Fix from $1,600 2025-12-02
Superduper\! HIGH 7.8
CVE-2025-61229

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight …

Fix: after 3.10
Fix from $1,950 2025-12-01
Wazuh MEDIUM 5.5
CVE-2025-54866

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "…

Fix: 4.13.0+
Fix from $1,600 2025-11-21
Logstare Collector HIGH 7.8
CVE-2025-58097

The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files with…

Fix: 2.4.2+
Fix from $1,950 2025-11-21
Fax Server HIGH 7.8
CVE-2025-34332

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Fax Server HIGH 7.8
CVE-2025-34333

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Unclassified MEDIUM 5.3
CVE-2025-54990

XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access …

Mitigation only
Fix from $1,600 2025-11-18