Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2019-16552
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacke…
Gerrit Trigger
after 2.30.1
MEDIUM 5.3
CVE-2019-19712
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been e…
Contao
after 4.8.5
HIGH 7.8
CVE-2019-14605
Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially e…
Setup And Configuration Software Platform Discovery Utility
Mitigation only
HIGH 7.8
CVE-2019-0134
Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially…
Dynamic Platform And Thermal Framework
after 8.3.10208.5643
HIGH 7.8
CVE-2019-14568
Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation o…
Rapid Storage Technology
17.7.0.1006+
HIGH 7.8
CVE-2019-14603
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenti…
Quartus Prime
19.3+
MEDIUM 5.3
CVE-2019-14861
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe pro…
Fedora
4.9.17 / 4.10.11+
MEDIUM 5.5
CVE-2019-19460
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default.…
Proaccess Space
after 5.5
MEDIUM 6.5
CVE-2019-19118
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user …
Django
2.1.15 / 2.2.8+
HIGH 7.3
CVE-2019-19490
LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrated by ROMFUSClient.exe.
Litemanager
No fix yet
HIGH 8.3
CVE-2018-20090
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and g…
Data Science Workbench
after 1.4.2
HIGH 7.2
CVE-2018-17860
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.
Cdh
after 5.14.0
MEDIUM 6.5
CVE-2019-13662
Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via…
Chrome
77.0.3865.75+
MEDIUM 6.2
CVE-2012-5578
Python keyring has insecure permissions on new databases allowing world-readable files to be created
Keyring
after 0.10
HIGH 8.8
CVE-2019-19202
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding …
Vtiger Crm
7.2.0+
HIGH 7.8
CVE-2019-17421
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local …
Manageengine Firewall Analyzer
Patch available
MEDIUM 5.5
CVE-2012-6136
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
Tuned
Mitigation only
HIGH 7.8
CVE-2019-14602
Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable…
Nuvoton Consumer Infrared
after 1.02.1002
HIGH 7.5
CVE-2010-5108
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and res…
Debian Linux
Mitigation only
HIGH 7.1
CVE-2019-4652
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local…
Spectrum Protect Plus
after 10.1.4
MEDIUM 5.5
CVE-2013-1425
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
Debian Linux
1.0.4+
MEDIUM 5.3
CVE-2019-1982
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Ci…
Firepower Services Software For Asa
Mitigation only
MEDIUM 6.1
CVE-2019-12752
The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attack…
Sonar
12.0.2+
MEDIUM 5.3
CVE-2019-18367
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
Teamcity
2019.1.2+
MEDIUM 5.3
CVE-2019-18369
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
Youtrack
2019.2.55152+
MEDIUM 5.3
CVE-2019-18366
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
Teamcity
2019.1.2+
HIGH 7.5
CVE-2012-5577
Python keyring lib before 0.10 created keyring files with world-readable permissions.
Keyring
0.10+
MEDIUM 6.5
CVE-2019-14925
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/sma…
Smartrtu Firmware
after 3.0
MEDIUM 6.5
CVE-2019-10469
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attac…
Kubernetes Ci
after 1.3
MEDIUM 6.5
CVE-2019-10470
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to en…
Kubernetes Ci
after 1.3