Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Inlong HIGH 7.5
CVE-2023-31453

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Inlong HIGH 7.5
CVE-2023-31454

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Akka Http MEDIUM 5.5
CVE-2023-33251

When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak pe…

Fix: 10.5.2+
Fix from $1,600 2023-05-21
Emui HIGH 7.5
CVE-2023-1692

The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,950 2023-05-20
Documentum Content Server HIGH 7.8
CVE-2023-31871

OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The sof…

Fix: 23.2+
Fix from $1,950 2023-05-18
Azure Vm Agents MEDIUM 6.5
CVE-2023-32990

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 852.v8d35f0960a_43
Fix from $1,600 2023-05-16
Saml Single Sign On HIGH 8.8
CVE-2023-32992

Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP r…

Fix: after 2.0.2
Fix from $1,950 2023-05-16
File Parameters HIGH 8.8
CVE-2023-32986EPSS 61%

Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameter…

Fix: after 285.287.v4b_7b_29d3469d
Fix from $1,950 2023-05-16
Planet MEDIUM 5.5
CVE-2023-32303

Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessibl…

Fix: 2.0.1+
Fix from $1,600 2023-05-12
Api Connect HIGH 8.8
CVE-2023-28522

IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585.

Fix: 10.0.1.11 / 10.0.5.2+
Fix from $1,950 2023-05-12
Access Controller MEDIUM 5.3
CVE-2023-31445

Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only u…

Fix: 2.1.1.2203171453+
Fix from $1,600 2023-05-11
Nuc Pro Software Suite HIGH 7.8
CVE-2022-46656

Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable e…

Fix: 2.0.0.3+
Fix from $1,950 2023-05-10
Quickassist Technology MEDIUM 5.5
CVE-2022-41771

Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user t…

Fix: 1.9.0+
Fix from $1,600 2023-05-10
Quickassist Technology HIGH 7.8
CVE-2022-41699

Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user t…

Fix: 1.9.0+
Fix from $1,950 2023-05-10
Vtune Profiler HIGH 7.8
CVE-2022-41658

Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enabl…

Fix: 2023.0+
Fix from $1,950 2023-05-10
Nuc Software Studio Service HIGH 7.8
CVE-2022-38103

Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to pote…

Fix: 1.17.38.0+
Fix from $1,950 2023-05-10
Exynos 5123 Firmware HIGH 7.8
CVE-2023-29092

An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, and Exynos 1080. Binding of a wron…

Mitigation only
Fix from $1,950 2023-05-09
GitLab MEDIUM 6.5
CVE-2023-2478EPSS 5%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6…

Fix: 15.9.7 / 15.10.6+
Fix from $1,600 2023-05-08
Ranger HIGH 8.1
CVE-2021-40331

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on …

Fix: after 2.3.0
Fix from $1,950 2023-05-05
Command \| Monitor HIGH 7.8
CVE-2023-28068

Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission vulnerability. A local authenticated malicious user can potenti…

Fix: after 10.9
Fix from $1,950 2023-05-05
Wallbox Glb Firmware HIGH 8.1
CVE-2023-30399

Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update package link…

Fix: after 189
Fix from $1,950 2023-05-04
Millegpg HIGH 7.8
CVE-2023-25438

An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying s…

No fix yet
Fix from $1,950 2023-05-04
Workforce Access CRITICAL 9.8
CVE-2023-0834

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects …

Fix: 8.1.0+
Fix from $2,300 2023-04-28
Desktop MEDIUM 5.5
CVE-2023-28123

A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN i…

Fix: 0.62.3.0+
Fix from $1,600 2023-04-19
Checkmk HIGH 8.8
CVE-2023-22294

Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.

Fix: 1.6.4+
Fix from $1,950 2023-04-18
Junos Os Evolved HIGH 8.2
CVE-2023-28960

An Incorrect Permission Assignment for Critical Resource vulnerability in Juniper Networks Junos OS Evolved allows a local, authenticated low-privile…

Mitigation only
Fix from $1,950 2023-04-17
Cubefs MEDIUM 6.5
CVE-2023-30512

CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list a…

Fix: after 3.2.1
Fix from $1,600 2023-04-12
Forticlient HIGH 8.1
CVE-2022-43946

Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (…

Fix: 7.0.8+
Fix from $1,950 2023-04-11
Screen MEDIUM 6.5
CVE-2023-24626

socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users t…

Fix: after 4.9.0
Fix from $1,600 2023-04-08
X11ssl Cf Firmware MEDIUM 5.5
CVE-2022-43309

Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.

No fix yet
Fix from $1,600 2023-04-07