Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Cloud Foundation MEDIUM 5.3
CVE-2024-37087

The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service…

Fix: 5.2+
Fix from $1,600 2024-06-25
Unclassified CRITICAL 9.8
CVE-2024-5163

Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.

No fix yet
Fix from $2,300 2024-06-17
Factorytalk View HIGH 8.8
CVE-2024-37369

A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C…

Fix: 14.0+
Fix from $1,950 2024-06-14
Velop Whw0101 Firmware MEDIUM 6.8
CVE-2024-36821

Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.

No fix yet
Fix from $1,600 2024-06-11
Powerpack Addons For Elementor HIGH 8.8
CVE-2024-3668

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due…

Fix: 2.10.18+
Fix from $1,950 2024-06-08
Advanced Core Operating System HIGH 7.8
CVE-2024-30369

A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privi…

Mitigation only
Fix from $1,950 2024-06-06
Unclassified HIGH 7.5
CVE-2024-29078

Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated …

Mitigation only
Fix from $1,950 2024-05-28
Qts HIGH 8.1
CVE-2024-21902

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploit…

Mitigation only
Fix from $1,950 2024-05-21
Extreme Tuning Utility HIGH 7.8
CVE-2024-21835

Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalatio…

Fix: 7.14.0.15+
Fix from $1,950 2024-05-16
Unclassified HIGH 7.8
CVE-2023-5936

On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the syste…

Mitigation only
Fix from $1,950 2024-05-15
Unclassified MEDIUM 6.8
CVE-2024-27108

Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products

No fix yet
Fix from $1,600 2024-05-14
Unclassified CRITICAL 9.1
CVE-2024-33499

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…

Mitigation only
Fix from $2,300 2024-05-14
Unclassified MEDIUM 6.3
CVE-2024-30208

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…

Mitigation only
Fix from $1,600 2024-05-14
Unclassified HIGH 7.4
CVE-2024-1486

Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

Mitigation only
Fix from $1,950 2024-05-14
Winflash HIGH 7.8
CVE-2023-35841

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of sys…

Fix: 4.5.0.0+
Fix from $1,950 2024-05-14
Security Guardium HIGH 7.8
CVE-2023-47712

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr…

Mitigation only
Fix from $1,950 2024-05-14
Viewpower HIGH 7.8
CVE-2023-51579

Voltronic Power ViewPower Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca…

Mitigation only
Fix from $1,950 2024-05-03
Simple Editor HIGH 7.8
CVE-2023-40516

LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate priv…

Mitigation only
Fix from $1,950 2024-05-03
Harmony Endpoint MEDIUM 6.7
CVE-2024-24912

A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit …

Mitigation only
Fix from $1,600 2024-05-01
Unclassified CRITICAL 9.8
CVE-2024-33435

Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback sy…

Mitigation only
Fix from $2,300 2024-04-29
Unclassified CRITICAL 9.4
CVE-2024-3375

Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained…

Mitigation only
Fix from $2,300 2024-04-29
Unclassified MEDIUM 6.2
CVE-2024-2905

A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit en…

Mitigation only
Fix from $1,600 2024-04-25
Unclassified MEDIUM 6.9
CVE-2024-32478

Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. Th…

Patch available
Fix from $1,600 2024-04-19
Brocade Sannav MEDIUM 6.5
CVE-2024-29964

Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access t…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Identity Agent HIGH 7.3
CVE-2024-24910

A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent f…

Fix: 4.2.712+
Fix from $1,950 2024-04-18
Peoplesoft Enterprise Hcm Benefits Administration MEDIUM 6.1
CVE-2024-21063

Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The suppo…

Mitigation only
Fix from $1,600 2024-04-16
Businessobjects Web Intelligence MEDIUM 6.5
CVE-2024-25646

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system informati…

Patch available
Fix from $1,600 2024-04-09
Emui MEDIUM 6.5
CVE-2023-52554

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Mitigation only
Fix from $1,600 2024-04-08
Emui HIGH 7.5
CVE-2023-52388

Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability.

Mitigation only
Fix from $1,950 2024-04-08
Harmonyos HIGH 7.5
CVE-2023-52715

The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2024-04-07