Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2023-28192
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A…
macOS
11.7.5 / 12.6.4+
CRITICAL 9.8
CVE-2023-23059
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installati…
Gv Edge Recording Manager
Mitigation only
CRITICAL 9.9
CVE-2023-22651
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook…
Rancher
after 2.7.2
HIGH 7.1
CVE-2023-28724
NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance M…
Nginx Api Connectivity Manager
1.3.0 / 1.5.0+
HIGH 8.8
CVE-2022-30759
In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and…
One Nds
after 20.9
HIGH 7.5
CVE-2023-1809
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbit…
Download Manager
6.3.0+
HIGH 7.5
CVE-2023-27035
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts v…
Obsidian
No fix yet
HIGH 7.0
CVE-2022-4568
A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.
System Update
5.08.01.0005+
HIGH 8.8
CVE-2023-29057
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privile…
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
MEDIUM 6.5
CVE-2023-29058
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through …
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
HIGH 7.8
CVE-2022-38583
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a l…
Sage 300
after 2022
HIGH 8.7
CVE-2021-23166
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write loca…
Odoo
after 15.0
HIGH 7.8
CVE-2022-31244
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
One Network Directory Server
No fix yet
MEDIUM 5.3
CVE-2023-29923EPSS 10%
PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.
Powerjob
No fix yet
HIGH 7.8
CVE-2021-41614
An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to the Exception Program Counter R…
Mor1kx Firmware
Mitigation only
HIGH 7.8
CVE-2023-28966
An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modif…
Junos Os Evolved
20.4+
HIGH 7.1
CVE-2023-27647
An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludash…
Lock Master
No fix yet
CRITICAL 9.8
CVE-2023-26918EPSS 6%
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed a…
File Replication Pro
No fix yet
HIGH 8.8
CVE-2023-22951
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be rea…
Cloud
No fix yet
HIGH 7.8
CVE-2023-25542
Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker …
Trusted Device Agent
5.3.0+
HIGH 8.8
CVE-2020-21514
An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.
Fluentd
No fix yet
HIGH 8.8
CVE-2023-25355
CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the `daemon` user on …
Sipxcom
after 21.04
HIGH 7.8
CVE-2023-25941
Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially explo…
Emc Powerscale Onefs
9.2.1.22 / 9.4.0.13+
HIGH 7.1
CVE-2023-0181
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly c…
Virtual Gpu
11.12 / 13.7+
HIGH 7.5
CVE-2022-48360
The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentialit…
Emui
Mitigation only
MEDIUM 5.5
CVE-2022-3146
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…
Openstack
Mitigation only
MEDIUM 5.5
CVE-2022-3101
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…
Openstack
Mitigation only
MEDIUM 5.5
CVE-2023-27593
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, an attacker…
Cilium
1.11.15 / 1.12.8+
MEDIUM 6.5
CVE-2022-46774
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …
Manage Application
Mitigation only
MEDIUM 5.4
CVE-2022-3758
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all ve…
GitLab
15.7.8 / 15.8.4+