Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.5 CVE-2023-1907 A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's s… Pgadmin 7.0+ Fix from $1,9502025-01-09 HIGH 7.8 CVE-2024-13206 A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveant… Mitigation only Fix from $1,9502025-01-09 HIGH 7.8 CVE-2024-13188 A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functi… Escan Anti Virus No fix yet Fix from $1,9502025-01-08 HIGH 7.5 CVE-2024-56447 Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service… Emui No fix yet Fix from $1,9502025-01-08 HIGH 7.5 CVE-2024-56440 Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnor… Emui No fix yet Fix from $1,9502025-01-08 HIGH 7.5 CVE-2023-52954 Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,9502025-01-08 CRITICAL 9.8 CVE-2022-41572 An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root… Eyesofnetwork after 5.3-11 Fix from $2,3002025-01-07 HIGH 8.4 CVE-2021-27285 An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt… Clusterengine No fix yet Fix from $1,9502025-01-06 HIGH 7.8 CVE-2024-11624 there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional exec… Android Mitigation only Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-53835 there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution priv… Android No fix yet Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-53840 there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with no additional execution priv… Android No fix yet Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-53841 In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privil… Android Mitigation only Fix from $1,9502025-01-03 HIGH 7.8 CVE-2024-43769 In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logi… Android Mitigation only Fix from $1,9502025-01-03 HIGH 7.8 CVE-2021-37000 Some Huawei wearables have a permission management vulnerability. Harmonyos No fix yet Fix from $1,9502024-12-28 HIGH 8.6 CVE-2024-55950 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlemen… Patch available Fix from $1,9502024-12-26 HIGH 7.8 CVE-2024-12903 Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder perm… Mitigation only Fix from $1,9502024-12-23 MEDIUM 5.5 CVE-2024-45819 PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied… Xen Patch available Fix from $1,6002024-12-19 HIGH 7.8 CVE-2024-4229 Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Develope… Mitigation only Fix from $1,9502024-12-19 HIGH 7.6 CVE-2024-49202 Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2… Mitigation only Fix from $1,9502024-12-18 HIGH 8.8 CVE-2024-38499 CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to… Mitigation only Fix from $1,9502024-12-17 MEDIUM 6.9 CVE-2024-12564 Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installi… Mitigation only Fix from $1,6002024-12-12 HIGH 7.8 CVE-2024-44224 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2.… macOS 13.7.2 / 14.7.2+ Fix from $1,9502024-12-12 HIGH 7.8 CVE-2024-11872 Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate pri… Launcher Mitigation only Fix from $1,9502024-12-12 HIGH 7.8 CVE-2024-8496 Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to ach… Workspace Control 10.18.40.0+ Fix from $1,9502024-12-11 HIGH 7.8 CVE-2024-9845 Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve lo… Automation 2024.4.0.1+ Fix from $1,9502024-12-11 HIGH 7.8 CVE-2024-10251 Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achie… Security Controls 2024.4.1+ Fix from $1,9502024-12-11 HIGH 7.8 CVE-2024-11597 Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local … Performance Manager 2023.3+ Fix from $1,9502024-12-11 HIGH 7.8 CVE-2024-11598 Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local … Application Control after 2023.3 Fix from $1,9502024-12-11 CRITICAL 9.8 CVE-2024-45494 An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared admini… Mitigation only Fix from $2,3002024-12-10 CRITICAL 9.8 CVE-2024-54751 COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. Mitigation only Fix from $2,3002024-12-10