Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Unclassified HIGH 8.5
CVE-2026-50602

A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 b…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.6
CVE-2026-73664

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-50544

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default ins…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.8
CVE-2026-65940

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.8
CVE-2026-14478

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC mess…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.5
CVE-2026-48790

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `s…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.0
CVE-2025-0046

Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.

No fix yet
Fix from $4,900 2026-08-11
Azure Sql Database HIGH 7.8
CVE-2026-63522

Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.0
CVE-2026-69108

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privileg…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.2
CVE-2026-4757

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.5
CVE-2026-63623

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.2
CVE-2026-15430

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.5
CVE-2026-68563

A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data`…

No fix yet
Fix from $1,600 2026-07-30
Unclassified CRITICAL 9.3
CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…

No fix yet
Fix from $2,300 2026-07-30
Ipados MEDIUM 5.5
CVE-2026-64707

A permissions issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Se…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
Unclassified HIGH 8.8
CVE-2026-61892

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.8
CVE-2026-16157

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside…

No fix yet
Fix from $1,950 2026-07-22
E Business Suite MEDIUM 6.3
CVE-2026-62519

Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affecte…

Fix: after 12.2.15
Fix from $1,600 2026-07-21
Agile Engineering Data Management CRITICAL 9.4
CVE-2026-61186

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is af…

No fix yet
Fix from $2,300 2026-07-21
Commerce Guided Search Platform Services CRITICAL 9.1
CVE-2026-61155

Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is a…

No fix yet
Fix from $2,300 2026-07-21
Solaris HIGH 7.1
CVE-2026-60659

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily expl…

No fix yet
Fix from $1,950 2026-07-21
Filegator HIGH 7.3
CVE-2026-63358

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' functio…

Fix: 7.14.2+
Fix from $1,950 2026-07-21
Unclassified HIGH 7.2
CVE-2026-44878

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the …

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 5.5
CVE-2026-65065

Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The se…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.2
CVE-2026-64613

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created …

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.9
CVE-2026-47134

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk p…

No fix yet
Fix from $1,600 2026-07-20
Cilium HIGH 8.8
CVE-2026-49445

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embe…

Fix: 1.17.14 / 1.18.8+
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.1
CVE-2026-15779

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the pat…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.1
CVE-2026-53486

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di…

Mitigation only
Fix from $2,300 2026-07-14