Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2024-1155 Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enab… Data Record Ad 2024_q1+ Fix from $1,9502024-02-20 HIGH 7.8 CVE-2024-1156 Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information an… Data Record Ad 2024_q1+ Fix from $1,9502024-02-20 MEDIUM 5.3 CVE-2024-25605 The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 be… Digital Experience Platform 7.2 / 7.4.3.5+ Fix from $1,6002024-02-20 HIGH 7.5 CVE-2023-52379 Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality. Emui Mitigation only Fix from $1,9502024-02-18 HIGH 7.5 CVE-2023-52362 Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,9502024-02-18 MEDIUM 5.9 CVE-2024-20921 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppo… Graalvm Mitigation only Fix from $1,6002024-02-17 HIGH 7.8 CVE-2024-0034 In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to … Android Patch available Fix from $1,9502024-02-16 HIGH 7.3 CVE-2024-1488 A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runti… Codeready Linux Builder Patch available Fix from $1,9502024-02-15 MEDIUM 6.7 CVE-2023-49721 An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot. Lxd 5.21.0+ Fix from $1,6002024-02-14 HIGH 7.8 CVE-2023-41231 Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable… Assistive Context Aware Toolkit 2.0.0+ Fix from $1,9502024-02-14 HIGH 7.8 CVE-2023-40154 Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable esca… System Usage Report 2.0.1901+ Fix from $1,9502024-02-14 HIGH 7.8 CVE-2023-34315 Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalati… Virtual Raid On Cpu 8.0.8.1001+ Fix from $1,9502024-02-14 MEDIUM 6.0 CVE-2023-29162 Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a… Advisor 2021.8 / 2021.10+ Fix from $1,6002024-02-14 HIGH 7.8 CVE-2023-28739 Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially … Chipset Device Software 10.1.19444.8378+ Fix from $1,9502024-02-14 HIGH 7.3 CVE-2023-38960 Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary… Raidenftpd No fix yet Fix from $1,9502024-02-13 HIGH 7.8 CVE-2023-50236 A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folder permissi… Polarion Alm 2404.0+ Fix from $1,9502024-02-13 HIGH 7.8 CVE-2024-24828 pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On u… Pkg after 5.8.1 Fix from $1,9502024-02-09 MEDIUM 5.5 CVE-2024-22430 Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user c… Powerscale Onefs 9.6.1+ Fix from $1,6002024-02-01 HIGH 7.8 CVE-2024-0833 In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer compon… Telerik Test Studio 2023.3.1330+ Fix from $1,9502024-01-31 HIGH 7.1 CVE-2024-21840 Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This … Storage Plug In 04.10.0+ Fix from $1,9502024-01-30 MEDIUM 5.5 CVE-2023-29081 A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authentica… Installshield Mitigation only Fix from $1,6002024-01-26 HIGH 7.5 CVE-2024-22301 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On… Albo Pretorio Online after 4.6.6 Fix from $1,9502024-01-24 MEDIUM 5.5 CVE-2022-4964 Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set. Ubuntu Pipewire Pulse Patch available Fix from $1,6002024-01-24 HIGH 7.1 CVE-2024-0770 A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function o… Iuclid No fix yet Fix from $1,9502024-01-21 HIGH 7.8 CVE-2023-29244 Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software installers b… Nuc P14e Laptop Element 5.4.1.4479+ Fix from $1,9502024-01-19 HIGH 8.8 CVE-2024-22409 DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user… Datahub 0.12.1+ Fix from $1,9502024-01-16 HIGH 7.8 CVE-2024-22428 Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user… Emc Idrac Service Module after 5.2.0.0 Fix from $1,9502024-01-16 HIGH 7.1 CVE-2023-6457 Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read… Tuning Manager 8.8.5-04+ Fix from $1,9502024-01-16 MEDIUM 5.5 CVE-2024-23301 Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to syst… Enterprise Linux after 2.7 Fix from $1,6002024-01-12 HIGH 7.8 CVE-2022-45793 Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which wil… Automation Software Sysmac Studio after 1.54 Fix from $1,9502024-01-10