Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Emui HIGH 7.5
CVE-2024-30413

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect avail…

No fix yet
Fix from $1,950 2024-04-07
Pebble MEDIUM 6.5
CVE-2024-3250

It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged …

Fix: 1.4.1 / 1.7.3+
Fix from $1,600 2024-04-04
Unclassified MEDIUM 6.7
CVE-2024-28589

An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary cod…

Mitigation only
Fix from $1,600 2024-04-03
Grab MEDIUM 5.5
CVE-2024-25956

Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentia…

Fix: 5.0.5+
Fix from $1,600 2024-03-26
Unclassified HIGH 7.3
CVE-2024-29187

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses Ge…

Patch available
Fix from $1,950 2024-03-24
Windows 10 21h2 MEDIUM 6.7
CVE-2024-21431

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

Fix: 10.0.19044.4170 / 10.0.19045.4170+
Fix from $1,600 2024-03-12
Netweaver Process Integration MEDIUM 5.3
CVE-2024-28163

Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver MEDIUM 5.3
CVE-2024-25644

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low…

Mitigation only
Fix from $1,600 2024-03-12
Netweaver Enterprise Portal MEDIUM 5.3
CVE-2024-25645

Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted…

No fix yet
Fix from $1,600 2024-03-12
Dp Golang HIGH 7.8
CVE-2024-27294

dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ow…

Fix: 1.2.7+
Fix from $1,950 2024-02-29
Android MEDIUM 5.0
CVE-2024-0019

In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a miss…

Patch available
Fix from $1,600 2024-02-16
Factorytalk Services Platform HIGH 8.8
CVE-2024-21915

A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic us…

Fix: 2.74+
Fix from $1,950 2024-02-16
Administrative Tools For Intel Network Adapters HIGH 7.8
CVE-2023-33870

Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable esca…

Fix: 28.2+
Fix from $1,950 2024-02-14
Netweaver Application Server Abap MEDIUM 5.3
CVE-2024-24740

SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64U…

Mitigation only
Fix from $1,600 2024-02-13
Solr HIGH 7.5
CVE-2023-50292

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This iss…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Spring Security MEDIUM 5.5
CVE-2023-34042

The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by a…

Fix: 5.8.7 / 6.0.7+
Fix from $1,600 2024-02-05
Qsync Central HIGH 8.1
CVE-2023-47564

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability cou…

Fix: 4.3.0.11 / 4.4.0.15+
Fix from $1,950 2024-02-02
Automation Studio HIGH 8.8
CVE-2020-24681

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This i…

Fix: 4.7.7.74 / 4.8.6.30+
Fix from $1,950 2024-02-02
Rapid Scada HIGH 7.8
CVE-2024-22016

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow pri…

Fix: after 5.8.4
Fix from $1,950 2024-02-02
Spring Cloud Contract MEDIUM 5.5
CVE-2024-22236

In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnera…

Fix: 3.1.10 / 4.0.5+
Fix from $1,600 2024-01-31
Ipados MEDIUM 6.2
CVE-2024-23223

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS…

Fix: 10.3 / 14.3+
Fix from $1,600 2024-01-23
Hid Event Filter Driver HIGH 7.8
CVE-2023-38541

Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2…

Fix: after 2.2.2.1
Fix from $1,950 2024-01-19
Emui HIGH 7.5
CVE-2023-52116

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exception…

Mitigation only
Fix from $1,950 2024-01-16
Emui HIGH 7.5
CVE-2023-52107

Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confiden…

Mitigation only
Fix from $1,950 2024-01-16
Ebuild For Slurm CRITICAL 9.8
CVE-2020-36770

pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem…

Fix: after 22.05.3
Fix from $2,300 2024-01-15
H8951 4g Esp Firmware HIGH 8.8
CVE-2023-49257

An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privi…

Fix: 2310271149+
Fix from $1,950 2024-01-12
Spectrum Power 7 HIGH 7.8
CVE-2023-44120

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administr…

Fix: 23q4+
Fix from $1,950 2024-01-09
Zxcloud Irai HIGH 7.8
CVE-2023-41776

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to es…

Fix: 7.23.32+
Fix from $1,950 2024-01-03
Online Notes Sharing System MEDIUM 5.4
CVE-2023-7055

A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /…

No fix yet
Fix from $1,600 2023-12-22
Multiprog CRITICAL 9.8
CVE-2023-0757

Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unaut…

Mitigation only
Fix from $2,300 2023-12-14