Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2025-15615
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiatio…
Wazuh
4.8.0+
HIGH 7.5
CVE-2026-32983
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiatio…
Wazuh
after 4.7.3
HIGH 7.8
CVE-2026-32680
The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to s…
Mitigation only
HIGH 8.2
CVE-2026-24063
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script …
Mitigation only
MEDIUM 6.2
CVE-2016-20029
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used…
No fix yet
MEDIUM 6.4
CVE-2025-8766
A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c…
Openshift Data Foundation
Mitigation only
MEDIUM 6.4
CVE-2025-57849
A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable …
Fuse
Mitigation only
HIGH 7.8
CVE-2026-3315
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA…
Visionline
1.34.0+
HIGH 7.8
CVE-2026-26131
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
.net
10.0.4+
MEDIUM 5.5
CVE-2026-28267
Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system direct…
Mitigation only
HIGH 7.8
CVE-2026-28727
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before buil…
Agent
17.0.41186+
MEDIUM 5.0
CVE-2026-28717
Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before buil…
Cyber Protect
17.0.41186+
HIGH 7.8
CVE-2026-26034
UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an att…
Ups Multi Ups Management Console
Mitigation only
MEDIUM 6.7
CVE-2026-21423
Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect default permissions vulnerability. A …
Powerscale Onefs
9.10.1.6 / 9.13.0.0+
HIGH 7.1
CVE-2026-2915
HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was
remediated…
System Event Utility
3.2.16+
MEDIUM 6.7
CVE-2026-27653
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary …
Securebrowser For Onegate
1.4.8 / 2.0.15+
HIGH 7.8
CVE-2026-23703
The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user ma…
Mitigation only
HIGH 7.8
CVE-2025-1789
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevate…
Genetec Update Service
2.10.6+
MEDIUM 6.1
CVE-2026-2026
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, poten…
Nessus Agent
11.0.4 / 11.1.2+
MEDIUM 6.7
CVE-2025-36511
Incorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an escalation…
Mitigation only
MEDIUM 6.7
CVE-2025-36522
Incorrect default permissions for some Intel(R) Chipset Software before version 10.1.20266.8668 or later. within Ring 3: User Applications may allow …
Mitigation only
MEDIUM 6.7
CVE-2025-32453
Incorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilege. Unpr…
Graphics Driver
6.12.28-linux-250521T070434Z / 25.30.1702.0+
MEDIUM 6.7
CVE-2025-31655
Incorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of privilege. U…
Mitigation only
MEDIUM 6.7
CVE-2025-22849
Incorrect default permissions for the Intel(R) Optane(TM) PMem management software before versions CR_MGMT_01.00.00.3584, CR_MGMT_02.00.00.4052, CR_M…
Mitigation only
HIGH 7.8
CVE-2026-25931
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats t…
Patch available
MEDIUM 6.2
CVE-2020-37160
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows syste…
No fix yet
MEDIUM 6.5
CVE-2025-15339
Tanium addressed an incorrect default permissions vulnerability in Discover.
Discover
4.10.118+
MEDIUM 6.5
CVE-2025-15340
Tanium addressed an incorrect default permissions vulnerability in Comply.
Comply
2.24.159 / 2.29.124+
MEDIUM 6.5
CVE-2025-15341
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
Benchmark
2.7.98 / 2.9.188+
MEDIUM 6.5
CVE-2025-15343
Tanium addressed an incorrect default permissions vulnerability in Enforce.
Enforce
2.7.367 / 2.8.601+