Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-23297
NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged a…
Mitigation only
MEDIUM 6.4
CVE-2025-57852
A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/passwd file being created with g…
Mitigation only
HIGH 8.4
CVE-2025-34191
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deploym…
Virtual Appliance Application
20.0.1923 / 22.0.843+
HIGH 7.7
CVE-2025-53947
A local attacker with low privileges on the Windows system where the
software is installed can exploit this vulnerability to corrupt
sensitive data…
Mitigation only
HIGH 8.8
CVE-2025-57625
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to esca…
Mitigation only
MEDIUM 5.5
CVE-2025-55111
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earl…
Control M\/agent
9.0.21+
HIGH 7.8
CVE-2025-43887
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attac…
Powerprotect Data Manager
19.21+
HIGH 7.8
CVE-2025-43725
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A l…
Powerprotect Data Manager
19.21+
HIGH 7.8
CVE-2025-10231
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-lev…
N Central
2025.3+
MEDIUM 5.1
CVE-2025-22425
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of pri…
Android
Patch available
CRITICAL 9.8
CVE-2024-43166
Incorrect Default Permissions vulnerability in Apache DolphinScheduler.
This issue affects Apache DolphinScheduler: before 3.2.2.
Users are recomme…
Dolphinscheduler
3.2.2+
HIGH 8.1
CVE-2024-46916
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesyst…
Vynamic Security Suite
after 4.3.0sr06
HIGH 7.8
CVE-2025-57846
Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacke…
Mitigation only
HIGH 7.8
CVE-2025-8098
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.
Pcmanager
5.1.120.7041+
MEDIUM 6.7
CVE-2025-27559
Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escal…
Mitigation only
MEDIUM 6.7
CVE-2025-26470
Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticated user t…
Mitigation only
MEDIUM 6.7
CVE-2025-20087
Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentially enable e…
Mitigation only
MEDIUM 6.7
CVE-2025-20023
Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation …
Mitigation only
HIGH 7.8
CVE-2025-8672
MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions
granted by the user to the …
Gimp
Mitigation only
MEDIUM 6.4
CVE-2025-7195
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK b…
Mitigation only
MEDIUM 6.5
CVE-2024-55398
4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
Exonaut
22.4+
HIGH 8.6
CVE-2025-44643
Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the p…
Mitigation only
MEDIUM 5.5
CVE-2025-41658
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
Mitigation only
HIGH 7.8
CVE-2025-52361
Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated lo…
Mitigation only
CRITICAL 9.1
CVE-2025-49084
CVE-2025-49084 is a vulnerability in the management console
of Absolute Secure Access prior to version 13.56. Attackers with administrative
access ca…
Secure Access
13.56+
CRITICAL 9.8
CVE-2025-54530
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
Teamcity
2025.07+
HIGH 7.1
CVE-2025-45467
Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure …
Go1 Firmware
No fix yet
HIGH 7.8
CVE-2025-8069
During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\s…
Mitigation only
CRITICAL 9.8
CVE-2025-8031
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vuln…
Firefox
128.13.0 / 140.1.0+
HIGH 7.0
CVE-2025-53945
apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical…
Patch available