Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Aim T Manageability Api HIGH 7.8
CVE-2023-31358

A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrar…

Fix: 6.0.0.2234+
Fix from $1,950 2025-05-13
Unclassified HIGH 7.3
CVE-2024-21960

Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalati…

Mitigation only
Fix from $1,950 2025-05-13
Unclassified HIGH 7.3
CVE-2024-36339

A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in a…

Mitigation only
Fix from $1,950 2025-05-13
Unclassified HIGH 8.2
CVE-2025-3528

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/pa…

Mitigation only
Fix from $1,950 2025-05-09
Harmonyos MEDIUM 5.5
CVE-2025-46587

Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2025-05-06
Harmonyos MEDIUM 5.5
CVE-2025-46586

Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-05-06
Backup CRITICAL 9.8
CVE-2025-43595

An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in…

Mitigation only
Fix from $2,300 2025-05-01
Unclassified HIGH 7.8
CVE-2025-42598

Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language o…

Mitigation only
Fix from $1,950 2025-04-28
Ngeniusone HIGH 7.1
CVE-2025-32981

NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

Fix: 6.4.0+
Fix from $1,950 2025-04-25
Unclassified HIGH 7.8
CVE-2025-24914

When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-direct…

Mitigation only
Fix from $1,950 2025-04-18
Mysql Connectors HIGH 7.5
CVE-2025-30706

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Diffic…

Fix: after 9.2.0
Fix from $1,950 2025-04-15
Ras Security HIGH 7.3
CVE-2025-30701

Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.…

Fix: after 23.7
Fix from $1,950 2025-04-15
Thinmanager HIGH 7.8
CVE-2025-3617

A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary f…

Fix: 14.0.2+
Fix from $1,950 2025-04-15
Unclassified HIGH 7.8
CVE-2025-23386

A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This is…

Mitigation only
Fix from $1,950 2025-04-10
Autoupdate HIGH 7.8
CVE-2025-29801

Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Fix: 4.78+
Fix from $1,950 2025-04-08
Student Manage HIGH 7.8
CVE-2025-29504

Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.

No fix yet
Fix from $1,950 2025-04-03
Lbt T300 T400 Firmware HIGH 7.8
CVE-2025-29570

An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check …

No fix yet
Fix from $1,950 2025-04-03
Unclassified HIGH 7.3
CVE-2025-0014

Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially result…

Mitigation only
Fix from $1,950 2025-04-02
Ipados CRITICAL 9.8
CVE-2025-30465

A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Son…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS HIGH 7.8
CVE-2025-24277

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4, macOS Sono…

Fix: 13.7.5 / 14.7.5+
Fix from $1,950 2025-03-31
macOS HIGH 7.8
CVE-2025-24267

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.…

Fix: 13.7.5 / 14.7.5+
Fix from $1,950 2025-03-31
Ipados CRITICAL 9.8
CVE-2025-24238

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ven…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS HIGH 7.8
CVE-2025-24234

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A mal…

Fix: 13.7.5 / 14.7.5+
Fix from $1,950 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24207

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24195

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS HIGH 7.8
CVE-2025-24170

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app…

Fix: 13.7.5 / 14.7.5+
Fix from $1,950 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24172

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
Unclassified MEDIUM 6.3
CVE-2025-2781

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. Thi…

Mitigation only
Fix from $1,600 2025-03-28
Unclassified MEDIUM 6.3
CVE-2025-2782

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This c…

Mitigation only
Fix from $1,600 2025-03-28
Unclassified CRITICAL 9.8
CVE-2025-25535

HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.

No fix yet
Fix from $2,300 2025-03-26