Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
CRITICAL 9.8 CVE-2024-28056 Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentica… Amplify Cli 12.10.1+ Fix from $2,3002024-04-15 MEDIUM 5.0 CVE-2024-21615 An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to access co… Junos 21.2+ Fix from $1,6002024-04-12 HIGH 8.8 CVE-2024-31442 Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users… Roblox Purchasing Hub 1.0.2+ Fix from $1,9502024-04-08 HIGH 7.8 CVE-2024-26574 Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSN… Filmora Mitigation only Fix from $1,9502024-04-08 HIGH 7.5 CVE-2023-52545 Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability. Emui No fix yet Fix from $1,9502024-04-08 MEDIUM 5.3 CVE-2023-52717 Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability. Emui No fix yet Fix from $1,6002024-04-07 CRITICAL 9.1 CVE-2024-30415 Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect avail… Emui No fix yet Fix from $2,3002024-04-07 HIGH 7.8 CVE-2024-30977 An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password compo… No fix yet Fix from $1,9502024-04-05 HIGH 7.8 CVE-2024-27674 Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an unprivilege… Macro Expert after 4.9.4 Fix from $1,9502024-04-03 HIGH 7.3 CVE-2024-0259 Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrit… Robot Schedule 3.04+ Fix from $1,9502024-03-28 HIGH 7.8 CVE-2024-25958 Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker … Grab 5.0.5+ Fix from $1,9502024-03-26 MEDIUM 6.2 CVE-2024-22085 An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world readable. G5dfr Firmware 1.2.1.12+ Fix from $1,6002024-03-20 MEDIUM 5.5 CVE-2024-25654 Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP applic… Unified Management Platform No fix yet Fix from $1,6002024-03-18 HIGH 7.8 CVE-2024-1605 BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissi… Control M 9.0.20.238 / 9.0.21.201+ Fix from $1,9502024-03-18 MEDIUM 5.5 CVE-2024-28862 The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Affected versions had overly pe… Rotp 6.3.0+ Fix from $1,6002024-03-16 MEDIUM 6.7 CVE-2023-28389 Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enabl… Mitigation only Fix from $1,6002024-03-14 MEDIUM 5.5 CVE-2024-20671 Microsoft Defender Security Feature Bypass Vulnerability Windows Defender Antimalware Platform 4.18.24010.12+ Fix from $1,6002024-03-12 MEDIUM 5.5 CVE-2024-23295 A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be a… Visionos 1.1+ Fix from $1,6002024-03-08 MEDIUM 5.5 CVE-2024-23201 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma … Ipados 10.3 / 12.7.4+ Fix from $1,6002024-03-08 HIGH 7.5 CVE-2024-22889 Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted req… Plone Mitigation only Fix from $1,9502024-03-06 MEDIUM 5.5 CVE-2024-20841 Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data. Account 14.8.00.3+ Fix from $1,6002024-03-05 MEDIUM 5.3 CVE-2024-20830 Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings. Android Mitigation only Fix from $1,6002024-03-05 HIGH 8.2 CVE-2024-20005 In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System executio… Android Mitigation only Fix from $1,9502024-03-04 HIGH 7.5 CVE-2023-49338 Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of lo… Couchbase Server 7.2.4+ Fix from $1,9502024-02-28 MEDIUM 5.5 CVE-2023-48678 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) b… Cyber Protect 16+ Fix from $1,6002024-02-27 HIGH 8.4 CVE-2023-50975 The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeE… Advanced Dashboard after 3.0.3 Fix from $1,9502024-02-21 HIGH 8.4 CVE-2023-7235 The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries w… Openvpn Gui 2.6.9+ Fix from $1,9502024-02-21 MEDIUM 5.5 CVE-2023-42945 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Blue… macOS Mitigation only Fix from $1,6002024-02-21 MEDIUM 5.5 CVE-2023-42953 A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadO… Ipad Os 10.1 / 17.1+ Fix from $1,6002024-02-21 HIGH 7.8 CVE-2023-42928 The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able to gain elevated privileges. Ipad Os 17.1+ Fix from $1,9502024-02-21