Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 8.5 CVE-2026-33590 Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution.… Patch available Fix from $1,9502026-05-28 HIGH 7.8 CVE-2026-49237 An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version… Multipass 1.16.3+ Fix from $1,9502026-05-28 HIGH 7.0 CVE-2026-44469 The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A lo… Development System 3.5.22.20+ Fix from $1,9502026-05-26 HIGH 7.8 CVE-2026-44468 The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local att… Development System 3.5.22.20+ Fix from $1,9502026-05-26 HIGH 8.4 CVE-2018-25359 Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by … No fix yet Fix from $1,9502026-05-25 HIGH 7.5 CVE-2025-32749 Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacke… Powerflex Appliance Intelligent Catalog 3.7.8.0 / 48.383.00+ Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-8487 Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEi… Moveit Automation 2025.0.11 / 2025.1.7+ Fix from $1,9502026-05-20 HIGH 8.1 CVE-2026-47107 Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted wi… Patch available Fix from $1,9502026-05-19 MEDIUM 6.9 CVE-2025-48516 Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse th… Mitigation only Fix from $1,6002026-05-15 HIGH 8.5 CVE-2026-0432 Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation result… Mitigation only Fix from $1,9502026-05-15 HIGH 7.0 CVE-2025-48512 Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to ach… Mitigation only Fix from $1,9502026-05-15 MEDIUM 6.8 CVE-2026-36742 Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode). Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.5 CVE-2026-21015 Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier. Android Mitigation only Fix from $1,6002026-05-13 MEDIUM 5.4 CVE-2026-20718 Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring 3: User Applications may allo… Mitigation only Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-41712 Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure betw… Spring Ai 1.0.7 / 1.1.6+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-45393 A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorr… Mitigation only Fix from $1,9502026-05-12 HIGH 8.5 CVE-2026-0539 Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting… Mitigation only Fix from $1,9502026-04-22 HIGH 8.2 CVE-2026-6823 HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["… Openharness 0.1.7+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-6819 HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /rel… Openharness 0.1.7+ Fix from $1,9502026-04-21 HIGH 7.8 CVE-2026-39454 SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A … Skymec It Manager after 2024.005.10a Fix from $1,9502026-04-20 MEDIUM 6.5 CVE-2026-30811 Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 thr… Pandora Fms 800.1+ Fix from $1,6002026-04-13 MEDIUM 5.5 CVE-2026-21013 Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information. Galaxy Wearable 2.2.68.26+ Fix from $1,6002026-04-13 HIGH 7.8 CVE-2026-25203 Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than … Mitigation only Fix from $1,9502026-04-10 MEDIUM 6.4 CVE-2025-57853 A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-w… Web Terminal Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-57854 A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being c… Openshift Update Service Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-58713 A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file bein… Process Automation Manager Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-57847 A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being crea… Ansible Automation Platform after 2.6 Fix from $1,6002026-04-08 MEDIUM 6.7 CVE-2025-57851 A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file bein… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002026-04-08 HIGH 7.3 CVE-2025-7024 Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may ex… Tetra Connectivity Server Mitigation only Fix from $1,9502026-04-03 HIGH 7.8 CVE-2026-21765 HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host mach… Bigfix Platform after 11.0.5 Fix from $1,9502026-04-02