Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2023-50612 Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive … Cloudexplorer Lite No fix yet Fix from $1,9502024-01-06 MEDIUM 6.4 CVE-2023-5536 A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their pr… Ubuntu Linux 24.04+ Fix from $1,6002023-12-12 HIGH 8.8 CVE-2021-3187 An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running… Privilege Management For Mac 5.7+ Fix from $1,9502023-12-11 MEDIUM 6.5 CVE-2023-28870 Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-… Secure Enterprise Client 12.22+ Fix from $1,6002023-12-09 CRITICAL 9.8 CVE-2023-46773 Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation. Emui Mitigation only Fix from $2,3002023-12-06 MEDIUM 5.3 CVE-2023-6273 Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to pe… Emui No fix yet Fix from $1,6002023-12-06 HIGH 7.5 CVE-2023-37572 Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_… Opc 5.30+ Fix from $1,9502023-12-05 MEDIUM 5.5 CVE-2023-40076 In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This … Android Patch available Fix from $1,6002023-12-04 CRITICAL 9.8 CVE-2023-21216 In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local e… Android Mitigation only Fix from $2,3002023-12-04 CRITICAL 9.8 CVE-2023-47462 Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing funct… Gl Ax1800 Firmware after 3.125 Fix from $2,3002023-11-29 HIGH 7.2 CVE-2023-6302 A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templat… Cszcms No fix yet Fix from $1,9502023-11-27 HIGH 8.8 CVE-2023-47250 In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with… Mprivacy Tools 2.0.159 / 4.0.406g+ Fix from $1,9502023-11-22 MEDIUM 5.5 CVE-2023-42774 in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions. Openharmony after 3.2.2 Fix from $1,6002023-11-20 HIGH 7.1 CVE-2023-3116 in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default per… Openharmony after 3.2.2 Fix from $1,9502023-11-20 MEDIUM 6.5 CVE-2023-40363 IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM… Infosphere Information Server Mitigation only Fix from $1,6002023-11-18 CRITICAL 9.8 CVE-2023-48648 Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creatio… Concrete Cms 8.5.13 / 9.2.2+ Fix from $2,3002023-11-17 MEDIUM 6.5 CVE-2023-47335 Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fl… Evo Nano Drone Firmware Mitigation only Fix from $1,6002023-11-16 HIGH 7.8 CVE-2023-41718 When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont… Secure Access Client No fix yet Fix from $1,9502023-11-15 HIGH 7.8 CVE-2023-35080 A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulne… Secure Access Client 22.6+ Fix from $1,9502023-11-15 HIGH 7.8 CVE-2023-32638 Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable esc… Arc Rgb Controller 1.06+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-27305 Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially ena… Iris Xe Graphics 31.0.101.4255+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-23583 Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable es… Debian Linux Mitigation only Fix from $1,9502023-11-14 CRITICAL 9.8 CVE-2023-43902 Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registere… Emsigner No fix yet Fix from $2,3002023-11-14 HIGH 7.8 CVE-2023-4706 A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to… Preload Directory Mitigation only Fix from $1,9502023-11-08 HIGH 7.5 CVE-2023-43984 Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_… Advanced Export Products Orders Cron Csv Excel after 4.4.7 Fix from $1,9502023-11-07 HIGH 7.8 CVE-2023-41726 Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability Avalanche 6.4.1.236+ Fix from $1,9502023-11-03 MEDIUM 6.5 CVE-2023-4091 A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS modu… Fedora 4.17.12 / 4.18.8+ Fix from $1,6002023-11-03 MEDIUM 6.7 CVE-2022-4575 A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with phys… Thinkpad 25 Firmware 1.45 / 1.49+ Fix from $1,6002023-10-30 HIGH 7.8 CVE-2023-5623 NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w… Nessus Network Monitor 6.3.0+ Fix from $1,9502023-10-26 HIGH 8.0 CVE-2023-45990 Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges. Wenwenai Cms No fix yet Fix from $1,9502023-10-25