Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2026-63425 During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.8 CVE-2026-65940 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. No fix yet Fix from $4,0002026-08-12 MEDIUM 5.5 CVE-2026-48790 Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `s… No fix yet Fix from $4,0002026-08-11 HIGH 7.3 CVE-2026-59119 Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. Powershell No fix yet Fix from $4,9002026-08-11 HIGH 7.2 CVE-2026-21074 Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege. No fix yet Fix from $4,9002026-08-10 HIGH 7.3 CVE-2026-4793 An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and condu… No fix yet Fix from $1,9502026-08-03 HIGH 7.8 CVE-2026-39874 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A… macOS 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 HIGH 7.8 CVE-2026-39875 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A… macOS 14.8.8 / 15.7.8+ Fix from $1,9502026-07-27 HIGH 8.3 CVE-2026-17497 NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the defa… No fix yet Fix from $1,9502026-07-26 HIGH 7.3 CVE-2026-16246 In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full… No fix yet Fix from $1,9502026-07-20 HIGH 7.3 CVE-2026-16247 In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %P… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.3 CVE-2024-58356 SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE R… Surrealdb 2.1.4+ Fix from $1,6002026-07-18 HIGH 8.8 CVE-2023-54366 SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables witho… Surrealdb 1.0.1+ Fix from $1,9502026-07-18 HIGH 7.8 CVE-2026-40952 CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers wit… Secure Access 14.55+ Fix from $1,9502026-07-15 HIGH 8.5 CVE-2026-61828 Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixO… Mitigation only Fix from $1,9502026-07-15 HIGH 8.2 CVE-2026-53657 Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver… Patch available Fix from $1,9502026-07-10 CRITICAL 9.4 CVE-2025-27462 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV dri… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27463 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27464 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive… Mitigation only Fix from $2,3002026-07-09 HIGH 7.8 CVE-2026-57895 Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folde… Mitigation only Fix from $1,9502026-07-08 HIGH 7.8 CVE-2026-57919 PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ a… Mitigation only Fix from $1,9502026-06-29 MEDIUM 5.3 CVE-2026-57924 In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details Youtrack 2026.2.16593+ Fix from $1,6002026-06-26 HIGH 8.1 CVE-2026-48725 Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to requ… Patch available Fix from $1,9502026-06-24 MEDIUM 5.5 CVE-2026-56301 Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstr… Nuxt 3.21.7 / 4.4.7+ Fix from $1,6002026-06-23 HIGH 8.8 CVE-2026-12602 Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permis… Mitigation only Fix from $1,9502026-06-22 MEDIUM 5.5 CVE-2026-53870 Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversati… Patch available Fix from $1,6002026-06-17 MEDIUM 6.8 CVE-2025-15642 Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to by… Mitigation only Fix from $1,6002026-06-17 MEDIUM 6.7 CVE-2026-50255 Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitr… Mitigation only Fix from $1,6002026-06-16 MEDIUM 5.5 CVE-2026-11931 Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local … Mitigation only Fix from $1,6002026-06-15 HIGH 8.8 CVE-2026-49157 Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The def… Activemq 5.19.7 / 6.2.6+ Fix from $1,9502026-06-01