Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
CRITICAL 9.8 CVE-2024-53351 Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges. Pipecd after 0.49.3 Fix from $2,3002025-03-21 HIGH 7.8 CVE-2025-24915 When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions fo… Mitigation only Fix from $1,9502025-03-21 MEDIUM 5.9 CVE-2025-27612 libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of… Patch available Fix from $1,6002025-03-21 MEDIUM 6.5 CVE-2024-54564 This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file … Ipados 1.3 / 14.6+ Fix from $1,6002025-03-21 MEDIUM 5.5 CVE-2024-0245 A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious a… Patch available Fix from $1,6002025-03-20 MEDIUM 5.3 CVE-2025-27926 In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are rea… Automation 5.8+ Fix from $1,6002025-03-10 MEDIUM 6.2 CVE-2025-20910 Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery. Wear Os Mitigation only Fix from $1,6002025-03-06 HIGH 7.8 CVE-2025-22447 Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is… Mitigation only Fix from $1,9502025-03-06 HIGH 7.8 CVE-2025-24864 Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is … Mitigation only Fix from $1,9502025-03-06 CRITICAL 9.8 CVE-2025-27682 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005. Vasion Print 1.0.735 / 20.0.1330+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27677 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interac… Vasion Print 20.0.1923 / 22.0.843+ Fix from $2,3002025-03-05 MEDIUM 5.5 CVE-2025-27521 Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service… Harmonyos No fix yet Fix from $1,6002025-03-04 MEDIUM 5.5 CVE-2024-58046 Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentialit… Harmonyos Mitigation only Fix from $1,6002025-03-04 MEDIUM 5.5 CVE-2024-58047 Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidenti… Harmonyos No fix yet Fix from $1,6002025-03-04 MEDIUM 5.5 CVE-2024-58049 Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidenti… Harmonyos Mitigation only Fix from $1,6002025-03-04 MEDIUM 5.5 CVE-2024-58050 Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentialit… Harmonyos No fix yet Fix from $1,6002025-03-04 MEDIUM 5.5 CVE-2024-58044 Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,6002025-03-04 CRITICAL 9.8 CVE-2025-27154 Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to vers… Spotipy 2.25.1+ Fix from $2,3002025-02-27 CRITICAL 9.8 CVE-2024-56525 In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a n… Mitigation only Fix from $2,3002025-02-24 MEDIUM 5.5 CVE-2025-21106 Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially… Recoverpoint For Virtual Machines Mitigation only Fix from $1,6002025-02-20 CRITICAL 9.8 CVE-2024-57604 An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component. Ezbookkeeping No fix yet Fix from $2,3002025-02-12 HIGH 7.8 CVE-2024-51440 An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component. Mitigation only Fix from $1,9502025-02-12 MEDIUM 6.7 CVE-2024-42419 Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially ena… Mitigation only Fix from $1,6002025-02-12 MEDIUM 6.7 CVE-2024-32942 Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially ena… Mitigation only Fix from $1,6002025-02-12 HIGH 7.3 CVE-2023-31360 Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacke… Mitigation only Fix from $1,9502025-02-11 CRITICAL 9.8 CVE-2024-55215 An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register. Trojan after 2.15.3 Fix from $2,3002025-02-07 HIGH 7.8 CVE-2024-11468 Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful expl… Mitigation only Fix from $1,9502025-02-04 CRITICAL 9.6 CVE-2025-24891 Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrit… Patch available Fix from $2,3002025-01-31 MEDIUM 5.5 CVE-2025-24788 snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET … Snowflake Connector 4.3.0+ Fix from $1,6002025-01-29 MEDIUM 5.5 CVE-2025-24795 The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op… Snowflake Connector 3.13.1+ Fix from $1,6002025-01-29