Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Bigfix Platform HIGH 7.8
CVE-2026-21765

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host mach…

Fix: after 11.0.5
Fix from $1,950 2026-04-02
Appsync HIGH 7.3
CVE-2026-22768

Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with loc…

Fix: 4.6.1.0+
Fix from $1,950 2026-04-01
Tigervnc CRITICAL 9.8
CVE-2026-34352

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, b…

Fix: 1.16.2+
Fix from $2,300 2026-03-26
Mattermost Server MEDIUM 5.5
CVE-2026-3113

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which…

Fix: 10.11.12 / 11.2.4+
Fix from $1,600 2026-03-26
Briefcase HIGH 7.3
CVE-2026-33430

Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and prior to version 0.3.26, if a…

Fix: 0.3.26+
Fix from $1,950 2026-03-26
Panorama Collaborative Operation \& Execution HIGH 7.5
CVE-2026-4761

When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the p…

Mitigation only
Fix from $1,950 2026-03-25
macOS MEDIUM 5.5
CVE-2026-28829

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Openclaw CRITICAL 9.9
CVE-2026-32048

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to …

Fix: 2026.3.1+
Fix from $2,300 2026-03-21
Halloy MEDIUM 5.5
CVE-2026-32810

Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates…

Fix: after 2026.4
Fix from $1,600 2026-03-20
Wazuh HIGH 7.2
CVE-2026-25770

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, …

Fix: 4.14.3+
Fix from $1,950 2026-03-17
Airflow MEDIUM 6.5
CVE-2026-26929

Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made wi…

Fix: 3.1.8+
Fix from $1,600 2026-03-17
Siyuan MEDIUM 6.5
CVE-2026-32704

SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminRole, allowing any authenticat…

Fix: 3.6.1+
Fix from $1,600 2026-03-16
Unclassified MEDIUM 6.8
CVE-2025-15037

An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by …

Mitigation only
Fix from $1,600 2026-03-12
Visionline HIGH 7.8
CVE-2026-3315

Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA…

Fix: 1.34.0+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-24291

Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Unclassified MEDIUM 6.5
CVE-2025-41712

An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is…

Mitigation only
Fix from $1,600 2026-03-10
Cyber Protect MEDIUM 5.5
CVE-2026-28725

Sensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis Cyber Protect 17 (…

Fix: 17.0.41186+
Fix from $1,600 2026-03-06
Filebrowser HIGH 8.1
CVE-2026-29188

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Pr…

Fix: 2.61.1+
Fix from $1,950 2026-03-05
Sfx2100 Firmware HIGH 7.8
CVE-2026-29126

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver al…

No fix yet
Fix from $1,950 2026-03-05
Openshift Container Platform MEDIUM 6.5
CVE-2025-12801

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi…

Mitigation only
Fix from $1,600 2026-03-04
App Auto Patch HIGH 7.8
CVE-2025-70341

Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.

Fix: after 3.4.2
Fix from $1,950 2026-03-04
Erase Install MEDIUM 6.6
CVE-2025-70342

erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthentic…

Fix: 41.0+
Fix from $1,600 2026-03-04
Unclassified MEDIUM 6.6
CVE-2026-24732

Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpic…

Mitigation only
Fix from $1,600 2026-03-04
System Event Utility HIGH 7.1
CVE-2026-2915

HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated…

Fix: 3.2.16+
Fix from $1,950 2026-03-03
Storage Scale HIGH 7.8
CVE-2025-14604

IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentiona…

Fix: 5.2.3.6 / 6.0.0.2+
Fix from $1,950 2026-03-03
Ntfs For Mac HIGH 7.8
CVE-2026-2637

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. The daemon exposes an NSConnec…

No fix yet
Fix from $1,950 2026-03-03
Junos Os Evolved CRITICAL 9.8
CVE-2026-21902EPSS 18%

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved…

Mitigation only
Fix from $2,300 2026-02-25
Opds Talon HIGH 7.8
CVE-2026-26102

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

Mitigation only
Fix from $1,950 2026-02-20
Opds Talon MEDIUM 5.5
CVE-2026-26095

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

Mitigation only
Fix from $1,600 2026-02-20
Opds Talon MEDIUM 5.5
CVE-2026-26096

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

Mitigation only
Fix from $1,600 2026-02-20