Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Pipecd CRITICAL 9.8
CVE-2024-53351

Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.

Fix: after 0.49.3
Fix from $2,300 2025-03-21
Unclassified HIGH 7.8
CVE-2025-24915

When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions fo…

Mitigation only
Fix from $1,950 2025-03-21
Unclassified MEDIUM 5.9
CVE-2025-27612

libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of…

Patch available
Fix from $1,600 2025-03-21
Ipados MEDIUM 6.5
CVE-2024-54564

This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file …

Fix: 1.3 / 14.6+
Fix from $1,600 2025-03-21
Unclassified MEDIUM 5.5
CVE-2024-0245

A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious a…

Patch available
Fix from $1,600 2025-03-20
Automation MEDIUM 5.3
CVE-2025-27926

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are rea…

Fix: 5.8+
Fix from $1,600 2025-03-10
Wear Os MEDIUM 6.2
CVE-2025-20910

Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

Mitigation only
Fix from $1,600 2025-03-06
Unclassified HIGH 7.8
CVE-2025-22447

Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is…

Mitigation only
Fix from $1,950 2025-03-06
Unclassified HIGH 7.8
CVE-2025-24864

Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is …

Mitigation only
Fix from $1,950 2025-03-06
Vasion Print CRITICAL 9.8
CVE-2025-27682

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.

Fix: 1.0.735 / 20.0.1330+
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27677

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interac…

Fix: 20.0.1923 / 22.0.843+
Fix from $2,300 2025-03-05
Harmonyos MEDIUM 5.5
CVE-2025-27521

Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service…

No fix yet
Fix from $1,600 2025-03-04
Harmonyos MEDIUM 5.5
CVE-2024-58046

Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentialit…

Mitigation only
Fix from $1,600 2025-03-04
Harmonyos MEDIUM 5.5
CVE-2024-58047

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidenti…

No fix yet
Fix from $1,600 2025-03-04
Harmonyos MEDIUM 5.5
CVE-2024-58049

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidenti…

Mitigation only
Fix from $1,600 2025-03-04
Harmonyos MEDIUM 5.5
CVE-2024-58050

Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentialit…

No fix yet
Fix from $1,600 2025-03-04
Emui MEDIUM 5.5
CVE-2024-58044

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-03-04
Spotipy CRITICAL 9.8
CVE-2025-27154

Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to vers…

Fix: 2.25.1+
Fix from $2,300 2025-02-27
Unclassified CRITICAL 9.8
CVE-2024-56525

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a n…

Mitigation only
Fix from $2,300 2025-02-24
Recoverpoint For Virtual Machines MEDIUM 5.5
CVE-2025-21106

Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially…

Mitigation only
Fix from $1,600 2025-02-20
Ezbookkeeping CRITICAL 9.8
CVE-2024-57604

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

No fix yet
Fix from $2,300 2025-02-12
Unclassified HIGH 7.8
CVE-2024-51440

An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.

Mitigation only
Fix from $1,950 2025-02-12
Unclassified MEDIUM 6.7
CVE-2024-42419

Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially ena…

Mitigation only
Fix from $1,600 2025-02-12
Unclassified MEDIUM 6.7
CVE-2024-32942

Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially ena…

Mitigation only
Fix from $1,600 2025-02-12
Unclassified HIGH 7.3
CVE-2023-31360

Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacke…

Mitigation only
Fix from $1,950 2025-02-11
Trojan CRITICAL 9.8
CVE-2024-55215

An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

Fix: after 2.15.3
Fix from $2,300 2025-02-07
Unclassified HIGH 7.8
CVE-2024-11468

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful expl…

Mitigation only
Fix from $1,950 2025-02-04
Unclassified CRITICAL 9.6
CVE-2025-24891

Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrit…

Patch available
Fix from $2,300 2025-01-31
Snowflake Connector MEDIUM 5.5
CVE-2025-24788

snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET …

Fix: 4.3.0+
Fix from $1,600 2025-01-29
Snowflake Connector MEDIUM 5.5
CVE-2025-24795

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op…

Fix: 3.13.1+
Fix from $1,600 2025-01-29