Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Unclassified HIGH 7.1
CVE-2024-42449EPSS 6%

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary fil…

Mitigation only
Fix from $1,950 2024-12-04
Confluence Data Center MEDIUM 6.4
CVE-2024-21703

This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows install…

Fix: 7.19.18 / 8.5.5+
Fix from $1,600 2024-11-27
Unclassified MEDIUM 5.9
CVE-2024-28955

Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredu…

Mitigation only
Fix from $1,600 2024-11-26
Pdf Editor HIGH 7.8
CVE-2024-9244

Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers t…

Fix: after 2024.2.3.25184
Fix from $1,950 2024-11-22
Pdf Editor HIGH 7.8
CVE-2024-9245

Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers t…

Fix: after 2024.2.3.25184
Fix from $1,950 2024-11-22
Panda Dome HIGH 7.8
CVE-2024-7245

Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala…

Mitigation only
Fix from $1,950 2024-11-22
Total Security HIGH 7.8
CVE-2024-6871

G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate…

Mitigation only
Fix from $1,950 2024-11-22
Notes Station 3 MEDIUM 6.0
CVE-2024-38646

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability c…

Fix: 3.9.7+
Fix from $1,600 2024-11-22
Unclassified MEDIUM 5.3
CVE-2024-11176

Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorre…

Mitigation only
Fix from $1,600 2024-11-20
Unclassified HIGH 7.1
CVE-2024-41974

A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lea…

Mitigation only
Fix from $1,950 2024-11-18
Unclassified MEDIUM 5.7
CVE-2024-41970

A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.

Mitigation only
Fix from $1,600 2024-11-18
Driver \& Support Assistant HIGH 7.8
CVE-2024-36294

Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalati…

Fix: 24.3.26.8+
Fix from $1,950 2024-11-13
Computing Improvement Program HIGH 7.8
CVE-2024-36276

Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalati…

Fix: 2.4.10852+
Fix from $1,950 2024-11-13
Connect Secure HIGH 7.8
CVE-2024-39709

Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (N…

Fix: 9.1 / 22.6+
Fix from $1,950 2024-11-13
Siport HIGH 7.8
CVE-2024-47783

A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation f…

Fix: 3.4.0+
Fix from $1,950 2024-11-12
Sinec Nms MEDIUM 6.5
CVE-2024-47808

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not prop…

Fix: 3.0+
Fix from $1,600 2024-11-12
Unclassified HIGH 7.8
CVE-2024-50590

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one o…

Mitigation only
Fix from $1,950 2024-11-08
Unclassified HIGH 8.6
CVE-2024-10526

Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL per…

Mitigation only
Fix from $1,950 2024-11-07
Secure Internet Access Enterprise Threatavert HIGH 7.1
CVE-2024-45164

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Po…

No fix yet
Fix from $1,950 2024-11-04
Unclassified HIGH 7.1
CVE-2024-0128

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful …

Mitigation only
Fix from $1,950 2024-10-26
Ovaledge HIGH 7.5
CVE-2022-30354

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is req…

Fix: 5.2.9+
Fix from $1,950 2024-10-25
Unclassified HIGH 7.3
CVE-2023-6729

Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified HIGH 7.8
CVE-2024-22029

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

Mitigation only
Fix from $1,950 2024-10-16
Unclassified CRITICAL 9.8
CVE-2024-10018

Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.

Mitigation only
Fix from $2,300 2024-10-16
Unclassified HIGH 7.5
CVE-2024-44729

Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privi…

Mitigation only
Fix from $1,950 2024-10-11
Taipy MEDIUM 6.5
CVE-2024-47833

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected v…

Fix: 4.0.0+
Fix from $1,600 2024-10-09
Endpoint Manager Mobile HIGH 7.8
CVE-2024-7612

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

Fix: 12.0.0.5 / 12.1.0.4+
Fix from $1,950 2024-10-08
Rg Nbs2009g P Firmware CRITICAL 9.8
CVE-2024-24117

Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login …

No fix yet
Fix from $2,300 2024-10-02
Vertica CRITICAL 9.8
CVE-2024-6360

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized acces…

Fix: 12.0.4-30 / 23.3.0-11+
Fix from $2,300 2024-10-02
Vault HIGH 8.8
CVE-2024-7594

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields o…

Fix: 1.15.15 / 1.16.10+
Fix from $1,950 2024-09-26