Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Unclassified HIGH 7.8
CVE-2025-23297

NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged a…

Mitigation only
Fix from $1,950 2025-10-01
Unclassified MEDIUM 6.4
CVE-2025-57852

A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/passwd file being created with g…

Mitigation only
Fix from $1,600 2025-09-30
Virtual Appliance Application HIGH 8.4
CVE-2025-34191

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deploym…

Fix: 20.0.1923 / 22.0.843+
Fix from $1,950 2025-09-19
Unclassified HIGH 7.7
CVE-2025-53947

A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data…

Mitigation only
Fix from $1,950 2025-09-18
Unclassified HIGH 8.8
CVE-2025-57625

CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to esca…

Mitigation only
Fix from $1,950 2025-09-16
Control M\/agent MEDIUM 5.5
CVE-2025-55111

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earl…

Fix: 9.0.21+
Fix from $1,600 2025-09-16
Powerprotect Data Manager HIGH 7.8
CVE-2025-43887

Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attac…

Fix: 19.21+
Fix from $1,950 2025-09-10
Powerprotect Data Manager HIGH 7.8
CVE-2025-43725

Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A l…

Fix: 19.21+
Fix from $1,950 2025-09-10
N Central HIGH 7.8
CVE-2025-10231

An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-lev…

Fix: 2025.3+
Fix from $1,950 2025-09-10
Android MEDIUM 5.1
CVE-2025-22425

In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of pri…

Patch available
Fix from $1,600 2025-09-04
Dolphinscheduler CRITICAL 9.8
CVE-2024-43166

Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recomme…

Fix: 3.2.2+
Fix from $2,300 2025-09-03
Vynamic Security Suite HIGH 8.1
CVE-2024-46916

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesyst…

Fix: after 4.3.0sr06
Fix from $1,950 2025-08-29
Unclassified HIGH 7.8
CVE-2025-57846

Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacke…

Mitigation only
Fix from $1,950 2025-08-27
Pcmanager HIGH 7.8
CVE-2025-8098

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.

Fix: 5.1.120.7041+
Fix from $1,950 2025-08-18
Unclassified MEDIUM 6.7
CVE-2025-27559

Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escal…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-26470

Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticated user t…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-20087

Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentially enable e…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-20023

Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation …

Mitigation only
Fix from $1,600 2025-08-12
Gimp HIGH 7.8
CVE-2025-8672

MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the …

Mitigation only
Fix from $1,950 2025-08-11
Unclassified MEDIUM 6.4
CVE-2025-7195

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK b…

Mitigation only
Fix from $1,600 2025-08-07
Exonaut MEDIUM 6.5
CVE-2024-55398

4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.

Fix: 22.4+
Fix from $1,600 2025-08-06
Unclassified HIGH 8.6
CVE-2025-44643

Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the p…

Mitigation only
Fix from $1,950 2025-08-04
Unclassified MEDIUM 5.5
CVE-2025-41658

CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

Mitigation only
Fix from $1,600 2025-08-04
Unclassified HIGH 7.8
CVE-2025-52361

Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated lo…

Mitigation only
Fix from $1,950 2025-08-01
Secure Access CRITICAL 9.1
CVE-2025-49084

CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access ca…

Fix: 13.56+
Fix from $2,300 2025-07-31
Teamcity CRITICAL 9.8
CVE-2025-54530

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

Fix: 2025.07+
Fix from $2,300 2025-07-28
Go1 Firmware HIGH 7.1
CVE-2025-45467

Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure …

No fix yet
Fix from $1,950 2025-07-25
Unclassified HIGH 7.8
CVE-2025-8069

During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\s…

Mitigation only
Fix from $1,950 2025-07-23
Firefox CRITICAL 9.8
CVE-2025-8031

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vuln…

Fix: 128.13.0 / 140.1.0+
Fix from $2,300 2025-07-22
Unclassified HIGH 7.0
CVE-2025-53945

apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical…

Patch available
Fix from $1,950 2025-07-18