Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2024-28056
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentica…
Amplify Cli
12.10.1+
MEDIUM 5.0
CVE-2024-21615
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access co…
Junos
21.2+
HIGH 8.8
CVE-2024-31442
Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users…
Roblox Purchasing Hub
1.0.2+
HIGH 7.8
CVE-2024-26574
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSN…
Filmora
Mitigation only
HIGH 7.5
CVE-2023-52545
Vulnerability of undefined permissions in the Calendar app.
Impact: Successful exploitation of this vulnerability will affect availability.
Emui
No fix yet
MEDIUM 5.3
CVE-2023-52717
Permission verification vulnerability in the lock screen module.
Impact: Successful exploitation of this vulnerability will affect availability.
Emui
No fix yet
CRITICAL 9.1
CVE-2024-30415
Vulnerability of improper permission control in the window management module.
Impact: Successful exploitation of this vulnerability will affect avail…
Emui
No fix yet
HIGH 7.8
CVE-2024-30977
An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password compo…
No fix yet
HIGH 7.8
CVE-2024-27674
Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an unprivilege…
Macro Expert
after 4.9.4
HIGH 7.3
CVE-2024-0259
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrit…
Robot Schedule
3.04+
HIGH 7.8
CVE-2024-25958
Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker …
Grab
5.0.5+
MEDIUM 6.2
CVE-2024-22085
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable.
G5dfr Firmware
1.2.1.12+
MEDIUM 5.5
CVE-2024-25654
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP applic…
Unified Management Platform
No fix yet
HIGH 7.8
CVE-2024-1605
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissi…
Control M
9.0.20.238 / 9.0.21.201+
MEDIUM 5.5
CVE-2024-28862
The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly pe…
Rotp
6.3.0+
MEDIUM 6.7
CVE-2023-28389
Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enabl…
Mitigation only
MEDIUM 5.5
CVE-2024-20671
Microsoft Defender Security Feature Bypass Vulnerability
Windows Defender Antimalware Platform
4.18.24010.12+
MEDIUM 5.5
CVE-2024-23295
A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be a…
Visionos
1.1+
MEDIUM 5.5
CVE-2024-23201
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma …
Ipados
10.3 / 12.7.4+
HIGH 7.5
CVE-2024-22889
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted req…
Plone
Mitigation only
MEDIUM 5.5
CVE-2024-20841
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.
Account
14.8.00.3+
MEDIUM 5.3
CVE-2024-20830
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
Android
Mitigation only
HIGH 8.2
CVE-2024-20005
In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executio…
Android
Mitigation only
HIGH 7.5
CVE-2023-49338
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of lo…
Couchbase Server
7.2.4+
MEDIUM 5.5
CVE-2023-48678
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) b…
Cyber Protect
16+
HIGH 8.4
CVE-2023-50975
The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeE…
Advanced Dashboard
after 3.0.3
HIGH 8.4
CVE-2023-7235
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries w…
Openvpn Gui
2.6.9+
MEDIUM 5.5
CVE-2023-42945
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Blue…
macOS
Mitigation only
MEDIUM 5.5
CVE-2023-42953
A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadO…
Ipad Os
10.1 / 17.1+
HIGH 7.8
CVE-2023-42928
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able to gain elevated privileges.
Ipad Os
17.1+