Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Solaris MEDIUM 6.0
CVE-2025-21551

Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploi…

Mitigation only
Fix from $1,600 2025-01-21
Unclassified HIGH 7.5
CVE-2025-0590

Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.

Mitigation only
Fix from $1,950 2025-01-20
Sterling Secure Proxy CRITICAL 9.1
CVE-2024-38337

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv…

Fix: 6.0.3.1+
Fix from $2,300 2025-01-19
Robotic Process Automation MEDIUM 6.7
CVE-2024-51448

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files i…

Fix: after 23.0.18
Fix from $1,600 2025-01-18
Windows 10 21h2 HIGH 7.8
CVE-2025-21325

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Fix: 10.0.19044.5371 / 10.0.19045.5371+
Fix from $1,950 2025-01-17
Unclassified MEDIUM 6.5
CVE-2024-39967

Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.

Mitigation only
Fix from $1,600 2025-01-15
Unclassified HIGH 8.8
CVE-2024-11497

An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.

No fix yet
Fix from $1,950 2025-01-14
Sap Basis HIGH 8.8
CVE-2025-0066

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted infor…

Patch available
Fix from $1,950 2025-01-14
Unclassified MEDIUM 5.5
CVE-2023-38037

ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user…

Mitigation only
Fix from $1,600 2025-01-09
Unclassified HIGH 8.8
CVE-2024-55411

An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying c…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified CRITICAL 9.1
CVE-2024-53931

The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) …

Mitigation only
Fix from $2,300 2025-01-06
Unclassified CRITICAL 9.1
CVE-2024-53932

The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any app…

Mitigation only
Fix from $2,300 2025-01-06
Powerscale Onefs MEDIUM 5.5
CVE-2024-47475

Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticate…

Fix: 9.4.0.20+
Fix from $1,600 2025-01-06
Unclassified MEDIUM 5.5
CVE-2024-49385

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 4…

Mitigation only
Fix from $1,600 2025-01-02
Deep Security Agent HIGH 7.3
CVE-2024-55955

An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow …

Mitigation only
Fix from $1,950 2024-12-31
Unclassified HIGH 7.6
CVE-2024-45497

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /va…

Mitigation only
Fix from $1,950 2024-12-31
I MEDIUM 6.8
CVE-2024-47104

IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the…

Mitigation only
Fix from $1,600 2024-12-18
Unclassified MEDIUM 6.9
CVE-2024-12564

Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installi…

Mitigation only
Fix from $1,600 2024-12-12
Accept Stripe Payments Using Contact Form 7 MEDIUM 5.3
CVE-2024-12255

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 …

Fix: 2.6+
Fix from $1,600 2024-12-12
Unclassified HIGH 7.1
CVE-2024-12363

Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to …

Mitigation only
Fix from $1,950 2024-12-11
Desktop \& Server Management HIGH 7.1
CVE-2024-7572

Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.

Fix: 2024.3.5740+
Fix from $1,950 2024-12-10
Standalone Sentry MEDIUM 5.5
CVE-2024-8540

Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive applicatio…

Fix: 9.20.2+
Fix from $1,600 2024-12-10
Endpoint Manager HIGH 7.1
CVE-2024-10256

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

Fix: 9.7.703 / 2024.4+
Fix from $1,950 2024-12-10
Unclassified MEDIUM 5.9
CVE-2024-8256

In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to …

Mitigation only
Fix from $1,600 2024-12-10
Robot Operating System CRITICAL 9.8
CVE-2024-41647

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…

Patch available
Fix from $2,300 2024-12-06
Open Automation Software HIGH 7.8
CVE-2024-11220

A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the se…

Fix: 20.0.0.76+
Fix from $1,950 2024-12-06
Unclassified MEDIUM 6.5
CVE-2024-45841

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earl…

Mitigation only
Fix from $1,600 2024-12-05
Remote Desktop Manager HIGH 8.1
CVE-2024-12149

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allow…

Fix: 2024.3.20.0+
Fix from $1,950 2024-12-04
Devolutions Server MEDIUM 5.0
CVE-2024-12151

Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permissio…

Fix: 2024.3.9.0+
Fix from $1,600 2024-12-04
Unclassified HIGH 8.2
CVE-2024-37574

The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without use…

Mitigation only
Fix from $1,950 2024-12-04