Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Opnsense HIGH 7.5
CVE-2023-39005

Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

Fix: 23.7+
Fix from $1,950 2023-08-09
Opnsense HIGH 7.5
CVE-2023-39003

OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.

Fix: 23.7+
Fix from $1,950 2023-08-09
Sicam Toolbox Ii HIGH 7.8
CVE-2022-39062

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product fo…

Fix: 07.10+
Fix from $1,950 2023-08-08
Cargo HIGH 7.3
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, d…

Fix: 0.72.2+
Fix from $1,950 2023-08-04
Jeesite MEDIUM 5.4
CVE-2023-38991

An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created…

No fix yet
Fix from $1,600 2023-08-04
Broadworks Application Delivery Platform HIGH 7.8
CVE-2023-20216

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevat…

Fix: 23.0.2023.05 / 24.0.2023.05+
Fix from $1,950 2023-08-03
Zenon HIGH 8.1
CVE-2023-3322

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…

Fix: after 11.0.0
Fix from $1,950 2023-07-24
Endpoint Security HIGH 7.8
CVE-2023-28133EPSS 6%

Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

Mitigation only
Fix from $1,950 2023-07-23
Sql Anywhere HIGH 7.1
CVE-2023-33990

SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with …

Mitigation only
Fix from $1,950 2023-07-11
S4core HIGH 7.3
CVE-2023-35870

When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could interce…

Mitigation only
Fix from $1,950 2023-07-11
Wireless Appliance Firmware HIGH 7.5
CVE-2022-44719

An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.

Fix: 6.0.13+
Fix from $1,950 2023-06-29
Netbackup Appliance HIGH 7.2
CVE-2023-37237

In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arb…

Fix: 4.1.0.1+
Fix from $1,950 2023-06-29
Endpoint Security MEDIUM 5.5
CVE-2023-35799

Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create a…

Fix: after 2.3.2
Fix from $1,600 2023-06-27
Dataease MEDIUM 6.5
CVE-2023-35168

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has …

Fix: 1.18.8+
Fix from $1,600 2023-06-26
Taier HIGH 7.5
CVE-2023-29860

An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCo…

No fix yet
Fix from $1,950 2023-06-23
Tomcat HIGH 7.5
CVE-2023-34981

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header…

Mitigation only
Fix from $1,950 2023-06-21
Harmonyos HIGH 8.2
CVE-2023-34154

Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to cr…

Fix: 2.0+
Fix from $1,950 2023-06-16
Cwx MEDIUM 5.4
CVE-2023-34797

Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information.

No fix yet
Fix from $1,600 2023-06-15
Publiccms CRITICAL 9.8
CVE-2023-34852

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

Fix: after 4.0.202302
Fix from $2,300 2023-06-15
Android MEDIUM 5.5
CVE-2023-21142

In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclos…

Patch available
Fix from $1,600 2023-06-15
Security Directory Suite Va HIGH 8.1
CVE-2022-33163

IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifie…

Patch available
Fix from $1,950 2023-06-15
Aws Codecommit Trigger MEDIUM 6.5
CVE-2023-35147

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attack…

Fix: after 3.0.12
Fix from $1,600 2023-06-14
Discourse MEDIUM 5.3
CVE-2023-31142

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passe…

Fix: 3.0.4+
Fix from $1,600 2023-06-13
Hutool HIGH 7.1
CVE-2023-33695

Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/io/FileUti…

Fix: after 5.8.17
Fix from $1,950 2023-06-13
Wincc HIGH 7.8
CVE-2023-30897

A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their ins…

Fix: 7.5.2.13+
Fix from $1,950 2023-06-13
Rex640 Pcl1 Firmware MEDIUM 6.1
CVE-2023-2876

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (fi…

Fix: 1.0.8 / 1.1.4+
Fix from $1,600 2023-06-13
Conprosys Hmi System HIGH 7.8
CVE-2023-28399

Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not …

Fix: 3.5.3+
Fix from $1,950 2023-06-01
Insight HIGH 7.3
CVE-2023-28346

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints…

No fix yet
Fix from $1,950 2023-05-31
Yank Note HIGH 8.8
CVE-2023-31874

Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process').

No fix yet
Fix from $1,950 2023-05-29
Mobiletrans HIGH 7.8
CVE-2023-31748

Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.

No fix yet
Fix from $1,950 2023-05-24