Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 5.5 CVE-2025-13193 A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivil… Mitigation only Fix from $1,6002025-11-17 HIGH 7.8 CVE-2025-13130 A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Conso… Mitigation only Fix from $1,9502025-11-13 HIGH 7.8 CVE-2025-13131 A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe… Mitigation only Fix from $1,9502025-11-13 MEDIUM 6.6 CVE-2025-8421 An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an a… Mitigation only Fix from $1,6002025-11-12 HIGH 7.3 CVE-2025-8485 An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated priv… App Store 9.0.2530.1027+ Fix from $1,9502025-11-12 HIGH 7.0 CVE-2025-61667 The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65… Mitigation only Fix from $1,9502025-11-12 HIGH 7.3 CVE-2025-11567 CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not proper… Mitigation only Fix from $1,9502025-11-12 HIGH 8.2 CVE-2025-32091 Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privil… Mitigation only Fix from $1,9502025-11-11 MEDIUM 6.7 CVE-2025-31940 Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3: User Applications may allow a… Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-30518 Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow an escalation of privilege… Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-27246 Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an e… Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-27711 Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications… Mitigation only Fix from $1,6002025-11-11 HIGH 7.5 CVE-2025-13025 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145. Firefox 145.0+ Fix from $1,9502025-11-11 HIGH 7.1 CVE-2025-10918 Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary… Endpoint Manager 2024+ Fix from $1,9502025-11-11 MEDIUM 5.3 CVE-2025-64436 KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, su… Kubevirt after 1.6.1 Fix from $1,6002025-11-07 MEDIUM 6.5 CVE-2025-43507 A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26… Ipados 26.1+ Fix from $1,6002025-11-04 MEDIUM 5.3 CVE-2025-43444 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS … Ipados 26.1+ Fix from $1,6002025-11-04 HIGH 8.4 CVE-2025-8432 Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user acc… Mitigation only Fix from $1,9502025-10-27 MEDIUM 6.2 CVE-2025-46185 An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of pas… Mitigation only Fix from $1,6002025-10-24 HIGH 7.8 CVE-2025-12100 Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driv… Mitigation only Fix from $1,9502025-10-23 MEDIUM 6.4 CVE-2025-57848 A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being c… Mitigation only Fix from $1,6002025-10-23 HIGH 7.8 CVE-2025-23347 NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability … Mitigation only Fix from $1,9502025-10-23 HIGH 7.8 CVE-2025-11575 Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas … Mitigation only Fix from $1,9502025-10-23 MEDIUM 6.4 CVE-2025-58712 A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file being created with group-wri… Mitigation only Fix from $1,6002025-10-22 HIGH 7.7 CVE-2025-61035 The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file and .seffaflik file, which i… Mitigation only Fix from $1,9502025-10-22 MEDIUM 6.9 CVE-2025-62661 Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth Experiments Extension allows… Mitigation only Fix from $1,6002025-10-21 HIGH 8.8 CVE-2025-62577 ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the manag… Mitigation only Fix from $1,9502025-10-20 MEDIUM 6.9 CVE-2025-62668 Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This is… Mitigation only Fix from $1,6002025-10-18 CRITICAL 9.8 CVE-2025-35062 Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit add… Project Center 2023.1+ Fix from $2,3002025-10-09 HIGH 8.8 CVE-2025-11535 MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affec… Mitigation only Fix from $1,9502025-10-08