Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2023-31358 A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrar… Aim T Manageability Api 6.0.0.2234+ Fix from $1,9502025-05-13 HIGH 7.3 CVE-2024-21960 Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalati… Mitigation only Fix from $1,9502025-05-13 HIGH 7.3 CVE-2024-36339 A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in a… Mitigation only Fix from $1,9502025-05-13 HIGH 8.2 CVE-2025-3528 A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/pa… Mitigation only Fix from $1,9502025-05-09 MEDIUM 5.5 CVE-2025-46587 Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,6002025-05-06 MEDIUM 5.5 CVE-2025-46586 Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002025-05-06 CRITICAL 9.8 CVE-2025-43595 An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in… Backup Mitigation only Fix from $2,3002025-05-01 HIGH 7.8 CVE-2025-42598 Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language o… Mitigation only Fix from $1,9502025-04-28 HIGH 7.1 CVE-2025-32981 NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File. Ngeniusone 6.4.0+ Fix from $1,9502025-04-25 HIGH 7.8 CVE-2025-24914 When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-direct… Mitigation only Fix from $1,9502025-04-18 HIGH 7.5 CVE-2025-30706 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Diffic… Mysql Connectors after 9.2.0 Fix from $1,9502025-04-15 HIGH 7.3 CVE-2025-30701 Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.… Ras Security after 23.7 Fix from $1,9502025-04-15 HIGH 7.8 CVE-2025-3617 A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary f… Thinmanager 14.0.2+ Fix from $1,9502025-04-15 HIGH 7.8 CVE-2025-23386 A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This is… Mitigation only Fix from $1,9502025-04-10 HIGH 7.8 CVE-2025-29801 Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. Autoupdate 4.78+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-29504 Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification. Student Manage No fix yet Fix from $1,9502025-04-03 HIGH 7.8 CVE-2025-29570 An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check … Lbt T300 T400 Firmware No fix yet Fix from $1,9502025-04-03 HIGH 7.3 CVE-2025-0014 Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially result… Mitigation only Fix from $1,9502025-04-02 CRITICAL 9.8 CVE-2025-30465 A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Son… Ipados 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 HIGH 7.8 CVE-2025-24277 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4, macOS Sono… macOS 13.7.5 / 14.7.5+ Fix from $1,9502025-03-31 HIGH 7.8 CVE-2025-24267 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.… macOS 13.7.5 / 14.7.5+ Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2025-24238 A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ven… Ipados 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 HIGH 7.8 CVE-2025-24234 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A mal… macOS 13.7.5 / 14.7.5+ Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2025-24207 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2025-24195 An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 HIGH 7.8 CVE-2025-24170 A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app… macOS 13.7.5 / 14.7.5+ Fix from $1,9502025-03-31 CRITICAL 9.8 CVE-2025-24172 A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 MEDIUM 6.3 CVE-2025-2781 The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. Thi… Mitigation only Fix from $1,6002025-03-28 MEDIUM 6.3 CVE-2025-2782 The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This c… Mitigation only Fix from $1,6002025-03-28 CRITICAL 9.8 CVE-2025-25535 HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request. No fix yet Fix from $2,3002025-03-26