Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-15336
Tanium addressed an incorrect default permissions vulnerability in Performance.
Performance
1.17.134 / 1.21.141+
MEDIUM 6.5
CVE-2025-15337
Tanium addressed an incorrect default permissions vulnerability in Patch.
Patch
3.17.2300 / 3.19.232+
MEDIUM 6.5
CVE-2025-15338
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
Partner Integration
1.0.224 / 1.2.33+
CRITICAL 9.8
CVE-2020-37129
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Atta…
Mitigation only
HIGH 8.8
CVE-2025-10314
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attac…
Mitigation only
HIGH 7.8
CVE-2025-69604
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package th…
Superduper\!
3.12+
HIGH 8.8
CVE-2026-24780
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…
Autogpt Platform
0.6.44+
MEDIUM 5.5
CVE-2026-24413
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not s…
Icinga
2.13.14 / 2.14.8+
MEDIUM 5.5
CVE-2026-24414
The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versi…
Icinga Powershell Framework
1.11.2 / 1.12.4+
HIGH 7.0
CVE-2025-13905
CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more execut…
Mitigation only
MEDIUM 6.7
CVE-2026-0705
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.4.…
Mitigation only
HIGH 7.1
CVE-2025-67230
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke ex…
Builder
0.33.0+
HIGH 8.8
CVE-2021-47852
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable wit…
No fix yet
MEDIUM 5.3
CVE-2025-55132
A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only …
Node.js
20.20.0 / 22.22.0+
HIGH 7.8
CVE-2021-47761
MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB…
No fix yet
MEDIUM 5.3
CVE-2025-67813
Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication
Kace Desktop Authority
11.3.2+
CRITICAL 9.8
CVE-2025-60262
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability …
Mc102 G Firmware
Mitigation only
HIGH 7.3
CVE-2025-64724
Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions…
Arduino Ide
2.3.7+
HIGH 7.8
CVE-2025-53398
The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,
Dell Color Management
after 3.3.008
HIGH 7.8
CVE-2025-53919
An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak…
Dell Color Management
after 3.3.008
MEDIUM 5.5
CVE-2025-43519
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. A…
macOS
14.8.3 / 15.7.3+
HIGH 7.8
CVE-2025-13155
An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated…
Mitigation only
HIGH 7.5
CVE-2025-59030
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
Recursor
5.1.9 / 5.2.7+
MEDIUM 6.4
CVE-2025-57850
A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with…
Mitigation only
HIGH 7.8
CVE-2025-61229
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight …
Superduper\!
after 3.10
MEDIUM 5.5
CVE-2025-54866
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "…
Wazuh
4.13.0+
HIGH 7.8
CVE-2025-58097
The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files with…
Logstare Collector
2.4.2+
HIGH 7.8
CVE-2025-34332
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back…
Fax Server
after 2.6.23
HIGH 7.8
CVE-2025-34333
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with…
Fax Server
after 2.6.23
MEDIUM 5.3
CVE-2025-54990
XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access …
Mitigation only