A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH ser…
A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker…
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account…
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevat…
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" …
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permissi…
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead …
An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdm…
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is worl…
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesy…
PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permissi…
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterpris…
The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take cont…
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the name…
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and…
Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected product…
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the r…
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the per…
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which …
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and im…
A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be a…