Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2020-24717
OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to…
Openzfs
after 0.8.4
MEDIUM 6.7
CVE-2020-3152
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute a…
Connected Mobile Experiences
Mitigation only
MEDIUM 5.3
CVE-2020-3484
A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to vie…
Vision Dynamic Signage Director
Mitigation only
MEDIUM 6.3
CVE-2020-3485
A vulnerability in the role-based access control (RBAC) functionality of the web management software of Cisco Vision Dynamic Signage Director could a…
Vision Dynamic Signage Director
Mitigation only
MEDIUM 6.5
CVE-2020-7824
A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vul…
Ipecs
after 2.10.14
HIGH 7.3
CVE-2020-1571
An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions.
A locally authenticated attacker could run arbitra…
Windows 10
Patch available
HIGH 8.2
CVE-2020-15145
In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit t…
Composer Setup
6.0.0+
HIGH 7.8
CVE-2020-8743
Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable …
Mailbox Interface Driver
Mitigation only
HIGH 7.8
CVE-2020-8763
Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potent…
Realsense D415 Firmware
6.1.160.14+
HIGH 7.8
CVE-2020-12287
Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enabl…
Distribution Of Openvino Toolkit
2020.2+
MEDIUM 6.5
CVE-2020-15821
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
Youtrack
2020.2.6881+
HIGH 7.8
CVE-2020-8026
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local att…
Backports Sle
after 2.6.2-4.2
HIGH 7.2
CVE-2020-8219
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full adminis…
Connect Secure
after 9.0
HIGH 7.5
CVE-2020-2077
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized att…
Package Analytics
after 04.0.0
HIGH 7.8
CVE-2020-10606
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This expl…
Pi Api
after 4.8.0.18
HIGH 7.8
CVE-2020-15852
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O po…
Linux Kernel
after 5.7.9
MEDIUM 6.7
CVE-2020-0122
In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions…
Android
Patch available
MEDIUM 5.3
CVE-2020-6165
SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms.…
Silverstripe
3.2.4 / 3.3.0+
HIGH 8.8
CVE-2020-11955
An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions.
Cmciii Pu 9333e0fb Firmware
after 6.17.00
MEDIUM 6.5
CVE-2020-12415
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirector…
Firefox
78.0+
MEDIUM 6.5
CVE-2020-12424
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of…
Firefox
78.0+
HIGH 7.8
CVE-2020-5974
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain dir…
Jetpack Software Development Kit
Mitigation only
MEDIUM 5.5
CVE-2020-15578
An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID …
Android
Mitigation only
HIGH 8.1
CVE-2020-5906
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blackl…
Big Ip Access Policy Manager
after 13.1.3
HIGH 7.8
CVE-2020-8022
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE …
Tomcat
8.0.53-29.32.1 / 9.0.35-3.39.1+
MEDIUM 5.3
CVE-2020-8024
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local a…
Hylafax\+
5.6.1-lp151.3.7 / 7.0.2-lp152.2.1+
HIGH 7.8
CVE-2020-15351
IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify perm…
Idrive
6.7.3.19+
CRITICAL 9.8
CVE-2020-10279
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system pre…
Mir100 Firmware
after 2.8.1.1
HIGH 7.8
CVE-2020-8903
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…
Guest Oslogin
after 20200507.00
HIGH 7.8
CVE-2020-8907
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…
Guest Oslogin
after 20200507.00