Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Unclassified MEDIUM 6.0
CVE-2025-12147

In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclu…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified MEDIUM 6.0
CVE-2025-12148

In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified HIGH 7.1
CVE-2025-62688

An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab…

Mitigation only
Fix from $1,950 2025-10-23
Unclassified CRITICAL 10.0
CVE-2025-12004

Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse…

Mitigation only
Fix from $2,300 2025-10-21
Unclassified MEDIUM 6.8
CVE-2025-31702

A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vul…

Mitigation only
Fix from $1,600 2025-10-15
Forticlient HIGH 7.8
CVE-2025-57741

An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all…

Fix: 7.2.12 / 7.4.4+
Fix from $1,950 2025-10-14
Digital Experience Platform MEDIUM 6.5
CVE-2025-62251

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA…

Fix: 7.4.3.119 / 2023.q3.9+
Fix from $1,600 2025-10-13
Unclassified MEDIUM 6.7
CVE-2025-8886

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A…

Mitigation only
Fix from $1,600 2025-10-10
Macforge HIGH 7.8
CVE-2025-10751

MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects MacForge: 1.2…

No fix yet
Fix from $1,950 2025-10-04
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34212

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments…

Fix: 20.0.1923 / 22.0.843+
Fix from $2,300 2025-09-29
Unclassified HIGH 7.8
CVE-2025-10541

iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure upda…

Mitigation only
Fix from $1,950 2025-09-25
Digital Experience Platform MEDIUM 5.3
CVE-2025-43808

The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA t…

Fix: 7.4.3.113 / 2023.Q4.9+
Fix from $1,600 2025-09-19
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34206

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material un…

Mitigation only
Fix from $2,300 2025-09-19
Virtual Appliance Application HIGH 7.8
CVE-2025-34189

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client…

Fix: 1.0.735 / 20.0.1330+
Fix from $1,950 2025-09-19
Unclassified HIGH 8.1
CVE-2025-54497

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgr…

Mitigation only
Fix from $1,950 2025-09-18
Unclassified HIGH 8.1
CVE-2025-52873

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgr…

Mitigation only
Fix from $1,950 2025-09-18
Repairit CRITICAL 9.1
CVE-2025-10643

Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authen…

Mitigation only
Fix from $2,300 2025-09-17
Benimpos HIGH 7.8
CVE-2025-57392

BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone and BUILTIN\Users groups FIL…

No fix yet
Fix from $1,950 2025-09-10
Unclassified CRITICAL 9.1
CVE-2025-40804

A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share …

Mitigation only
Fix from $2,300 2025-09-09
Unclassified HIGH 7.5
CVE-2025-41664

A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission …

Mitigation only
Fix from $1,950 2025-09-08
Roo Code CRITICAL 9.8
CVE-2025-58372

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS C…

Fix: 3.26.0+
Fix from $2,300 2025-09-05
MongoDB MEDIUM 6.5
CVE-2025-10059

An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is …

Fix: 6.0.24 / 7.0.18+
Fix from $1,600 2025-09-05
Unclassified HIGH 7.3
CVE-2025-23258

NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker with low privileges to escalate …

No fix yet
Fix from $1,950 2025-09-04
Unclassified HIGH 7.3
CVE-2025-23257

NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privileges to escalate privileges. A…

No fix yet
Fix from $1,950 2025-09-04
Transformation Advisor MEDIUM 6.7
CVE-2025-36193

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation in…

Fix: 4.3.2+
Fix from $1,600 2025-09-03
macOS HIGH 7.8
CVE-2025-43268

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root p…

Fix: 15.6+
Fix from $1,950 2025-08-29
Unclassified HIGH 7.8
CVE-2025-9578

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 7.0
CVE-2025-53396

Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier), which may al…

Mitigation only
Fix from $1,950 2025-08-28
Thinos HIGH 7.8
CVE-2025-43729

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A local low-privileg…

Fix: 2508+
Fix from $1,950 2025-08-27
Unclassified CRITICAL 9.4
CVE-2025-30063

The configuration file containing database logins and passwords is readable by any local user.

Mitigation only
Fix from $2,300 2025-08-27