Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Mysql Server MEDIUM 6.5
CVE-2025-30688

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4…

Fix: after 9.2.0
Fix from $1,600 2025-04-15
Mysql Server MEDIUM 6.5
CVE-2025-30682

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4…

Fix: after 9.2.0
Fix from $1,600 2025-04-15
Mysql Server MEDIUM 6.5
CVE-2025-30687

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.41, 8.4…

Fix: after 9.2.0
Fix from $1,600 2025-04-15
Secure Backup MEDIUM 6.7
CVE-2025-21578

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.…

Patch available
Fix from $1,600 2025-04-15
Taegis Endpoint Agent HIGH 7.8
CVE-2024-13861

A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitra…

Fix: 1.3.10+
Fix from $1,950 2025-04-11
Unclassified MEDIUM 5.5
CVE-2025-25041

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHO…

Mitigation only
Fix from $1,600 2025-04-01
Unclassified HIGH 8.4
CVE-2025-2098

Fast CAD Reader application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS …

Mitigation only
Fix from $1,950 2025-03-26
Core Flight System CRITICAL 9.8
CVE-2025-25373

The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

No fix yet
Fix from $2,300 2025-03-25
Unclassified HIGH 8.5
CVE-2024-10209

An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local …

Mitigation only
Fix from $1,950 2025-03-25
Thinos HIGH 7.8
CVE-2025-27688

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit thi…

Fix: after 2408
Fix from $1,950 2025-03-18
Below MEDIUM 6.8
CVE-2025-27591

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below…

Fix: 0.9.0+
Fix from $1,600 2025-03-11
Secure Access Client HIGH 7.8
CVE-2025-22454

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privilege…

Fix: 22.7+
Fix from $1,950 2025-03-11
Unclassified HIGH 8.4
CVE-2025-1413

DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security pra…

Mitigation only
Fix from $1,950 2025-02-28
Arcgis Allsource HIGH 7.3
CVE-2025-1067

There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the …

Mitigation only
Fix from $1,950 2025-02-25
Metabase MEDIUM 6.5
CVE-2025-27141

Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and p…

Fix: 1.50.36 / 1.51.14+
Fix from $1,600 2025-02-24
Secure Access Client HIGH 7.1
CVE-2024-13813

Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.

Fix: 22.8+
Fix from $1,950 2025-02-11
Unclassified HIGH 7.0
CVE-2025-23403

A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The affected device do not proper…

Mitigation only
Fix from $1,950 2025-02-11
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2025-0064

Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rig…

Patch available
Fix from $1,600 2025-02-11
Asterisk CRITICAL 9.8
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: thi…

Fix: after 22.5.1
Fix from $2,300 2025-02-05
Unclassified HIGH 7.5
CVE-2024-57068

A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Denial of Service (DoS) via supp…

Mitigation only
Fix from $1,950 2025-02-05
Security Verify Access MEDIUM 6.7
CVE-2024-45657

IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to i…

Fix: 10.0.9.0+
Fix from $1,600 2025-02-04
Unclassified MEDIUM 6.5
CVE-2025-0374

When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version…

Mitigation only
Fix from $1,600 2025-01-30
Unclassified HIGH 8.0
CVE-2025-24527

An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, t…

Mitigation only
Fix from $1,950 2025-01-29
Hive MEDIUM 5.5
CVE-2024-29869

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set exp…

Fix: 4.0.1+
Fix from $1,600 2025-01-28
Unclassified HIGH 7.0
CVE-2025-24481

An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions be…

Mitigation only
Fix from $1,950 2025-01-28
Cmsimple HIGH 7.5
CVE-2024-57547

Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functional…

No fix yet
Fix from $1,950 2025-01-27
Unclassified HIGH 7.1
CVE-2024-46881

Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in En…

Mitigation only
Fix from $1,950 2025-01-26
Vm Virtualbox HIGH 7.3
CVE-2025-21571

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.24 / 7.1.6+
Fix from $1,950 2025-01-21
Agile Product Lifecycle Management HIGH 8.1
CVE-2025-21564

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that …

Mitigation only
Fix from $1,950 2025-01-21
Mysql Server MEDIUM 6.5
CVE-2025-21566

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.1.0 and prior. …

Fix: after 9.1.0
Fix from $1,600 2025-01-21