Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
H8951 4g Esp Firmware HIGH 8.8
CVE-2023-49257

An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privi…

Fix: 2310271149+
Fix from $1,950 2024-01-12
Spectrum Power 7 HIGH 7.8
CVE-2023-44120

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administr…

Fix: 23q4+
Fix from $1,950 2024-01-09
Zxcloud Irai HIGH 7.8
CVE-2023-41776

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to es…

Fix: 7.23.32+
Fix from $1,950 2024-01-03
Online Notes Sharing System MEDIUM 5.4
CVE-2023-7055

A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /…

No fix yet
Fix from $1,600 2023-12-22
Multiprog CRITICAL 9.8
CVE-2023-0757

Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unaut…

Mitigation only
Fix from $2,300 2023-12-14
Automationworx Software Suite CRITICAL 9.8
CVE-2023-46141

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthen…

Mitigation only
Fix from $2,300 2023-12-14
Axc F 1152 Firmware HIGH 8.8
CVE-2023-46142

A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full …

Fix: after 2024.0
Fix from $1,950 2023-12-14
Zxcloud Irai HIGH 7.8
CVE-2023-25648

There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileg…

Fix: 7.23.21+
Fix from $1,950 2023-12-14
Remote Desktop Manager CRITICAL 9.8
CVE-2023-6593

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the applicati…

Fix: 2023.3.5.0+
Fix from $2,300 2023-12-12
Graphical User Interface HIGH 7.3
CVE-2023-49580

SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to …

Mitigation only
Fix from $1,950 2023-12-12
macOS MEDIUM 5.5
CVE-2023-42924

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app may be able to access sensit…

Fix: 13.6.3 / 14.2+
Fix from $1,600 2023-12-12
Mullvad Vpn HIGH 7.8
CVE-2023-50446

An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow any local unprivileged user to …

Fix: after 2023.5
Fix from $1,950 2023-12-10
Pyinstaller HIGH 7.8
CVE-2023-49797

PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application, elevated as a privileged pr…

Fix: 5.13.1+
Fix from $1,950 2023-12-09
Ngeniuspulse CRITICAL 9.1
CVE-2023-40302

NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability

Mitigation only
Fix from $2,300 2023-12-07
Forgejo CRITICAL 9.1
CVE-2023-49946

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This al…

Fix: 1.20.5-1+
Fix from $2,300 2023-12-03
Wp Hotel Booking MEDIUM 5.4
CVE-2023-5651

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be del…

Fix: 2.0.8+
Fix from $1,600 2023-11-20
Prowatch HIGH 7.8
CVE-2023-6179

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker cou…

Mitigation only
Fix from $1,950 2023-11-17
Xxl Job MEDIUM 5.4
CVE-2023-48087

xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.

No fix yet
Fix from $1,600 2023-11-15
Rapid Storage Technology HIGH 7.8
CVE-2023-39230

Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potent…

Fix: 16.8.5.1014.9+
Fix from $1,950 2023-11-14
Server Configuration Utility HIGH 7.8
CVE-2023-34997

Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated…

Fix: 16.0.9+
Fix from $1,950 2023-11-14
Simics Simulator HIGH 7.8
CVE-2023-34314

Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable …

Fix: 1.7.2+
Fix from $1,950 2023-11-14
Nuc Pro Software Suite HIGH 7.8
CVE-2022-41700

Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user t…

Fix: 2.0.0.9+
Fix from $1,950 2023-11-14
Nuc Watchdog Timer Utility HIGH 7.8
CVE-2022-33898

Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated user to p…

Fix: 2.0.21.0+
Fix from $1,950 2023-11-14
Fortimail MEDIUM 5.4
CVE-2023-36633

An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker …

Fix: 7.0.6 / 7.2.3+
Fix from $1,600 2023-11-14
Endpoint Security HIGH 7.8
CVE-2023-28134

Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first o…

No fix yet
Fix from $1,950 2023-11-12
Cortex Xsoar MEDIUM 6.7
CVE-2023-3282

A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a …

Fix: 6.10.0+
Fix from $1,600 2023-11-08
Topografix Data Plugin MEDIUM 5.5
CVE-2023-5136

An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulne…

Mitigation only
Fix from $1,600 2023-11-08
Inventory Management System HIGH 8.8
CVE-2023-46449

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the pass…

No fix yet
Fix from $1,950 2023-10-26
macOS MEDIUM 6.5
CVE-2023-42861

A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's…

Fix: 14.1+
Fix from $1,600 2023-10-25
Eisbaer Scada CRITICAL 9.8
CVE-2023-42489

EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource

Fix: after 3.0.6433.1964
Fix from $2,300 2023-10-25