Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.1 CVE-2024-40805 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchO… Ipados 10.6 / 14.6+ Fix from $1,9502024-07-29 MEDIUM 5.5 CVE-2024-27888 A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sonoma 14.4. An app may be a… macOS 14.4+ Fix from $1,6002024-07-29 HIGH 7.8 CVE-2024-42053 The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user c… Streamer 3.6.0.0+ Fix from $1,9502024-07-28 HIGH 8.8 CVE-2024-36541 Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's … Logging Operator Mitigation only Fix from $1,9502024-07-24 MEDIUM 5.5 CVE-2024-6122 An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosu… Systemlink after 2024 Fix from $1,6002024-07-22 MEDIUM 6.1 CVE-2024-5321 A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Aut… Mitigation only Fix from $1,6002024-07-18 MEDIUM 5.4 CVE-2024-21122 Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that… Peoplesoft Enterprise Hcm Shared Components Mitigation only Fix from $1,6002024-07-16 MEDIUM 5.5 CVE-2024-6326 An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this… Factorytalk Policy Manager Mitigation only Fix from $1,6002024-07-16 MEDIUM 6.5 CVE-2024-6325 The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-ad… Factorytalk Policy Manager Mitigation only Fix from $1,6002024-07-16 HIGH 7.8 CVE-2024-32861 Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions. Mitigation only Fix from $1,9502024-07-16 MEDIUM 5.5 CVE-2024-3779 Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security prod… Internet Security 11.0.12012.0 / 11.0.15004.0+ Fix from $1,6002024-07-16 HIGH 8.8 CVE-2024-6148 Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5 Workspace 2404.1+ Fix from $1,9502024-07-10 MEDIUM 5.5 CVE-2024-31312 In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposi… Android Patch available Fix from $1,6002024-07-09 HIGH 8.8 CVE-2024-22062 There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permis… Zxcloud Irai 7.23.40+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-3904 Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "… Mitigation only Fix from $1,9502024-07-04 MEDIUM 6.5 CVE-2024-2819 Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This… Ops Center Common Services 11.0.2-00+ Fix from $1,6002024-07-02 HIGH 7.8 CVE-2024-4679 Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi J… Mitigation only Fix from $1,9502024-07-02 MEDIUM 5.5 CVE-2024-35139 IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incor… Security Access Manager after 10.0.7.1 Fix from $1,6002024-06-28 MEDIUM 5.9 CVE-2024-39347 Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows m… Router Manager 1.2.5-8227 / 1.3.1-9346+ Fix from $1,6002024-06-28 MEDIUM 6.5 CVE-2023-38370 IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious pa… Security Access Manager after 10.0.7.1 Fix from $1,6002024-06-27 MEDIUM 5.3 CVE-2024-6238 pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation dire… Pgadmin 4 8.9+ Fix from $1,6002024-06-25 HIGH 7.7 CVE-2024-36495 The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read … Mitigation only Fix from $1,9502024-06-24 HIGH 7.8 CVE-2024-38459 langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue … Langchain Experimental 0.0.61+ Fix from $1,9502024-06-16 MEDIUM 6.7 CVE-2024-27180 An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL. No fix yet Fix from $1,6002024-06-14 HIGH 7.4 CVE-2024-27171 A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affecte… Mitigation only Fix from $1,9502024-06-14 HIGH 7.4 CVE-2024-27166 Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/m… No fix yet Fix from $1,9502024-06-14 HIGH 7.4 CVE-2024-27167 Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicio… Mitigation only Fix from $1,9502024-06-14 HIGH 7.7 CVE-2024-27155 The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The progr… Mitigation only Fix from $1,9502024-06-14 HIGH 7.4 CVE-2024-27150 The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for th… No fix yet Fix from $1,9502024-06-14 HIGH 7.4 CVE-2024-27151 The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The progr… No fix yet Fix from $1,9502024-06-14