Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 6.5 CVE-2025-15336 Tanium addressed an incorrect default permissions vulnerability in Performance. Performance 1.17.134 / 1.21.141+ Fix from $1,6002026-02-05 MEDIUM 6.5 CVE-2025-15337 Tanium addressed an incorrect default permissions vulnerability in Patch. Patch 3.17.2300 / 3.19.232+ Fix from $1,6002026-02-05 MEDIUM 6.5 CVE-2025-15338 Tanium addressed an incorrect default permissions vulnerability in Partner Integration. Partner Integration 1.0.224 / 1.2.33+ Fix from $1,6002026-02-05 CRITICAL 9.8 CVE-2020-37129 Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Atta… Mitigation only Fix from $2,3002026-02-05 HIGH 8.8 CVE-2025-10314 Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attac… Mitigation only Fix from $1,9502026-02-05 HIGH 7.8 CVE-2025-69604 An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package th… Superduper\! 3.12+ Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-24780 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.44+ Fix from $1,9502026-01-29 MEDIUM 5.5 CVE-2026-24413 Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not s… Icinga 2.13.14 / 2.14.8+ Fix from $1,6002026-01-29 MEDIUM 5.5 CVE-2026-24414 The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versi… Icinga Powershell Framework 1.11.2 / 1.12.4+ Fix from $1,6002026-01-29 HIGH 7.0 CVE-2025-13905 CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more execut… Mitigation only Fix from $1,9502026-01-29 MEDIUM 6.7 CVE-2026-0705 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.4.… Mitigation only Fix from $1,6002026-01-27 HIGH 7.1 CVE-2025-67230 Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke ex… Builder 0.33.0+ Fix from $1,9502026-01-23 HIGH 8.8 CVE-2021-47852 Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable wit… No fix yet Fix from $1,9502026-01-21 MEDIUM 5.3 CVE-2025-55132 A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only … Node.js 20.20.0 / 22.22.0+ Fix from $1,6002026-01-20 HIGH 7.8 CVE-2021-47761 MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB… No fix yet Fix from $1,9502026-01-15 MEDIUM 5.3 CVE-2025-67813 Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication Kace Desktop Authority 11.3.2+ Fix from $1,6002026-01-12 CRITICAL 9.8 CVE-2025-60262 An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability … Mc102 G Firmware Mitigation only Fix from $2,3002026-01-06 HIGH 7.3 CVE-2025-64724 Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions… Arduino Ide 2.3.7+ Fix from $1,9502025-12-18 HIGH 7.8 CVE-2025-53398 The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions, Dell Color Management after 3.3.008 Fix from $1,9502025-12-17 HIGH 7.8 CVE-2025-53919 An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak… Dell Color Management after 3.3.008 Fix from $1,9502025-12-17 MEDIUM 5.5 CVE-2025-43519 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. A… macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 HIGH 7.8 CVE-2025-13155 An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated… Mitigation only Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-59030 An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. Recursor 5.1.9 / 5.2.7+ Fix from $1,9502025-12-09 MEDIUM 6.4 CVE-2025-57850 A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with… Mitigation only Fix from $1,6002025-12-02 HIGH 7.8 CVE-2025-61229 An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight … Superduper\! after 3.10 Fix from $1,9502025-12-01 MEDIUM 5.5 CVE-2025-54866 Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "… Wazuh 4.13.0+ Fix from $1,6002025-11-21 HIGH 7.8 CVE-2025-58097 The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files with… Logstare Collector 2.4.2+ Fix from $1,9502025-11-21 HIGH 7.8 CVE-2025-34332 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back… Fax Server after 2.6.23 Fix from $1,9502025-11-19 HIGH 7.8 CVE-2025-34333 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with… Fax Server after 2.6.23 Fix from $1,9502025-11-19 MEDIUM 5.3 CVE-2025-54990 XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access … Mitigation only Fix from $1,6002025-11-18