Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Unclassified HIGH 8.5
CVE-2026-9789

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P…

Mitigation only
Fix from $1,950 2026-05-28
Vantara Pentaho Data Integration And Analytics MEDIUM 6.3
CVE-2026-2254

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain…

Fix: 10.2.0.7 / 11.0.0.0+
Fix from $1,600 2026-05-27
macOS MEDIUM 5.5
CVE-2025-43290

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app …

Fix: 14.8 / 15.7+
Fix from $1,600 2026-05-26
Unclassified HIGH 7.8
CVE-2026-25112

A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.

No fix yet
Fix from $1,950 2026-05-26
\ HIGH 7.5
CVE-2026-42497

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() pas…

Fix: 3.08+
Fix from $1,950 2026-05-26
Unclassified HIGH 8.5
CVE-2026-9489

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p…

Mitigation only
Fix from $1,950 2026-05-25
Summarize MEDIUM 5.5
CVE-2026-45246

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users t…

Fix: 0.15.1+
Fix from $1,600 2026-05-18
Www\ MEDIUM 5.3
CVE-2026-8612

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response f…

Fix: 2.00+
Fix from $1,600 2026-05-15
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-42937

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These…

Fix: after 17.5.1.4
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-41959

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 7.9
CVE-2026-41217

A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or adm…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-40462

Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated att…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Endpoint Manager HIGH 7.8
CVE-2026-8110

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate th…

Fix: after 2022
Fix from $1,950 2026-05-12
Axis Os HIGH 7.3
CVE-2026-0541

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege esc…

Fix: 12.9.32+
Fix from $1,950 2026-05-12
Axis Os HIGH 8.8
CVE-2026-1185

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escala…

Fix: 12.10.37+
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2026-41489

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and …

Mitigation only
Fix from $1,950 2026-05-11
Unclassified MEDIUM 6.1
CVE-2026-45222

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions t…

Patch available
Fix from $1,600 2026-05-11
Nitrosense HIGH 7.8
CVE-2026-8069

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use…

Fix: 3.00.3198 / 3.01.3056+
Fix from $1,950 2026-05-08
Agent HIGH 7.8
CVE-2026-41288

Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local use…

Fix: 1.25.03.0000+
Fix from $1,950 2026-05-06
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Openclaw MEDIUM 5.5
CVE-2026-41366

OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary…

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Coreutils HIGH 7.1
CVE-2026-35341

A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a F…

No fix yet
Fix from $1,950 2026-04-22
FreeBSD MEDIUM 6.2
CVE-2026-6386

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which…

Mitigation only
Fix from $1,600 2026-04-22
Livepatch Client MEDIUM 5.5
CVE-2026-6369

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a…

Fix: 10.15.0+
Fix from $1,600 2026-04-20
Unclassified HIGH 7.8
CVE-2026-22676

Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by …

Mitigation only
Fix from $1,950 2026-04-15
Pyroscope CRITICAL 9.1
CVE-2025-41118

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (CO…

Fix: 1.15.2+
Fix from $2,300 2026-04-15
Android MEDIUM 6.8
CVE-2026-21011

Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.

Mitigation only
Fix from $1,600 2026-04-13
Insight Agent MEDIUM 5.5
CVE-2026-4482

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read a…

Fix: 4.1.0.2+
Fix from $1,600 2026-04-10
Powerprotect Data Manager MEDIUM 5.5
CVE-2026-28264

Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low p…

Fix: 20.1.0.0+
Fix from $1,600 2026-04-08
True Image MEDIUM 6.7
CVE-2026-33271

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902.

Fix: 2026+
Fix from $1,600 2026-04-02