Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2024-53351
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
Pipecd
after 0.49.3
HIGH 7.8
CVE-2025-24915
When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions fo…
Mitigation only
MEDIUM 5.9
CVE-2025-27612
libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the tenant builder accepts a list of…
Patch available
MEDIUM 6.5
CVE-2024-54564
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file …
Ipados
1.3 / 14.6+
MEDIUM 5.5
CVE-2024-0245
A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious a…
Patch available
MEDIUM 5.3
CVE-2025-27926
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are rea…
Automation
5.8+
MEDIUM 6.2
CVE-2025-20910
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.
Wear Os
Mitigation only
HIGH 7.8
CVE-2025-22447
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is…
Mitigation only
HIGH 7.8
CVE-2025-24864
Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is …
Mitigation only
CRITICAL 9.8
CVE-2025-27682
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.
Vasion Print
1.0.735 / 20.0.1330+
CRITICAL 9.8
CVE-2025-27677
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interac…
Vasion Print
20.0.1923 / 22.0.843+
MEDIUM 5.5
CVE-2025-27521
Vulnerability of improper access permission in the process management module
Impact: Successful exploitation of this vulnerability may affect service…
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2024-58046
Permission management vulnerability in the lock screen module
Impact: Successful exploitation of this vulnerability may affect service confidentialit…
Harmonyos
Mitigation only
MEDIUM 5.5
CVE-2024-58047
Permission verification vulnerability in the media library module
Impact: Successful exploitation of this vulnerability may affect service confidenti…
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2024-58049
Permission verification vulnerability in the media library module
Impact: Successful exploitation of this vulnerability may affect service confidenti…
Harmonyos
Mitigation only
MEDIUM 5.5
CVE-2024-58050
Vulnerability of improper access permission in the HDC module
Impact: Successful exploitation of this vulnerability may affect service confidentialit…
Harmonyos
No fix yet
MEDIUM 5.5
CVE-2024-58044
Permission verification bypass vulnerability in the notification module
Impact: Successful exploitation of this vulnerability may affect availability.
Emui
No fix yet
CRITICAL 9.8
CVE-2025-27154
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to vers…
Spotipy
2.25.1+
CRITICAL 9.8
CVE-2024-56525
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a n…
Mitigation only
MEDIUM 5.5
CVE-2025-21106
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially…
Recoverpoint For Virtual Machines
Mitigation only
CRITICAL 9.8
CVE-2024-57604
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
Ezbookkeeping
No fix yet
HIGH 7.8
CVE-2024-51440
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
Mitigation only
MEDIUM 6.7
CVE-2024-42419
Incorrect default permissions for some Intel(R) GPA and Intel(R) GPA Framework software installers may allow an authenticated user to potentially ena…
Mitigation only
MEDIUM 6.7
CVE-2024-32942
Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially ena…
Mitigation only
HIGH 7.3
CVE-2023-31360
Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacke…
Mitigation only
CRITICAL 9.8
CVE-2024-55215
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
Trojan
after 2.15.3
HIGH 7.8
CVE-2024-11468
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful expl…
Mitigation only
CRITICAL 9.6
CVE-2025-24891
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrit…
Patch available
MEDIUM 5.5
CVE-2025-24788
snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET …
Snowflake Connector
4.3.0+
MEDIUM 5.5
CVE-2025-24795
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op…
Snowflake Connector
3.13.1+