Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 6.5 CVE-2024-8037 Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to t… Juju 2.9.51 / 3.1.10+ Fix from $1,6002024-10-02 MEDIUM 5.9 CVE-2024-46544 Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configu… Tomcat Connectors 1.2.50+ Fix from $1,6002024-09-23 MEDIUM 6.5 CVE-2022-25776 Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Us… Mautic 4.4.12 / 5.0.4+ Fix from $1,6002024-09-18 MEDIUM 5.5 CVE-2024-44135 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. An app may be able to acc… macOS 14.7+ Fix from $1,6002024-09-17 MEDIUM 5.5 CVE-2024-44151 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An ap… macOS 13.7 / 14.7+ Fix from $1,6002024-09-17 HIGH 8.8 CVE-2024-39924EPSS 13% An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization pr… Vaultwarden Mitigation only Fix from $1,9502024-09-13 HIGH 8.8 CVE-2024-8533 A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permi… 2800c Optixpanel Compact Firmware 4.0.2.106 / 4.0.2.116+ Fix from $1,9502024-09-12 MEDIUM 6.5 CVE-2024-38222 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Edge 128.0.2739.42+ Fix from $1,6002024-09-12 HIGH 7.8 CVE-2024-40654 In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40655 In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background d… Android Patch available Fix from $1,9502024-09-11 MEDIUM 5.5 CVE-2024-34648 Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data. Android Mitigation only Fix from $1,6002024-09-04 MEDIUM 5.5 CVE-2024-34018 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build … Snap Deploy 6+ Fix from $1,6002024-08-29 HIGH 7.5 CVE-2024-44760 Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attacke… Enterprise Management System after 18.8 Fix from $1,9502024-08-28 HIGH 7.1 CVE-2023-45896 ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distr… Patch available Fix from $1,9502024-08-28 HIGH 7.8 CVE-2024-43791 RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that the… Request Store Mitigation only Fix from $1,9502024-08-23 HIGH 7.8 CVE-2024-4763 An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could … Mitigation only Fix from $1,9502024-08-16 HIGH 7.8 CVE-2024-2175 An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that c… Mitigation only Fix from $1,9502024-08-16 HIGH 8.8 CVE-2024-42681 Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component. Xxl Job No fix yet Fix from $1,9502024-08-15 MEDIUM 5.5 CVE-2024-27461 Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentially enable denial of service vi… Memory And Storage Tool Gui 2.5.0+ Fix from $1,6002024-08-14 HIGH 7.8 CVE-2024-26025 Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalati… Advisor 2024.1+ Fix from $1,9502024-08-14 MEDIUM 6.7 CVE-2024-23974 Incorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially enable escalation of privilege … Mitigation only Fix from $1,6002024-08-14 HIGH 7.8 CVE-2024-23495 Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially e… Distribution For Gdb 2024.0.1 / 2024.1+ Fix from $1,9502024-08-14 MEDIUM 6.7 CVE-2024-22378 Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authe… Mitigation only Fix from $1,6002024-08-14 MEDIUM 6.7 CVE-2023-43747 Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 may allow an authenticated user… Mitigation only Fix from $1,6002024-08-14 HIGH 7.8 CVE-2023-31349 Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting … Uprof 4.1.424 / 4.2.816+ Fix from $1,9502024-08-13 MEDIUM 6.3 CVE-2024-6640 In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Requests, a crafted Echo Request pa… Mitigation only Fix from $1,6002024-08-12 MEDIUM 5.5 CVE-2024-34616 Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data. Android Mitigation only Fix from $1,6002024-08-07 HIGH 8.1 CVE-2024-7525 It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of r… Firefox 115.14.0 / 129.0+ Fix from $1,9502024-08-06 HIGH 7.8 CVE-2024-43114 In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions Teamcity 2024.07.1+ Fix from $1,9502024-08-06 HIGH 7.8 CVE-2024-6974 Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34. Cato Client 5.10.34+ Fix from $1,9502024-07-31