Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Android HIGH 7.5
CVE-2025-0093

In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to re…

Mitigation only
Fix from $1,950 2025-08-26
Chrome CRITICAL 9.6
CVE-2025-4609

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to poten…

Fix: 136.0.7103.113+
Fix from $2,300 2025-08-22
Smart Deploy HIGH 7.8
CVE-2025-52094

Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via the \HKLM\SYSTEM\Setup\SmartD…

Fix: 3.0.2046+
Fix from $1,950 2025-08-22
Emc Idrac Service Module MEDIUM 5.3
CVE-2025-38742

Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low pr…

Fix: 6.0.3.0+
Fix from $1,600 2025-08-21
Agent Zero HIGH 7.3
CVE-2025-55524

Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.

Fix: 0.9.0+
Fix from $1,950 2025-08-21
Unclassified HIGH 8.8
CVE-2025-27216

Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate p…

Mitigation only
Fix from $1,950 2025-08-21
Firefox CRITICAL 9.8
CVE-2025-8042

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 14…

Fix: 141.0+
Fix from $2,300 2025-08-19
GitLab MEDIUM 5.0
CVE-2025-5819

An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could ha…

Fix: 17.11.6 / 18.0.4+
Fix from $1,600 2025-08-13
Unclassified HIGH 7.8
CVE-2025-50675

GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory i…

Mitigation only
Fix from $1,950 2025-08-07
Harmonyos MEDIUM 5.7
CVE-2025-54618

Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confid…

No fix yet
Fix from $1,600 2025-08-06
Freefloat Ftp Server CRITICAL 9.8
CVE-2012-10030

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive syste…

Mitigation only
Fix from $2,300 2025-08-05
Liquidfiles HIGH 8.8
CVE-2025-46093

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by l…

Fix: 4.1.2+
Fix from $1,950 2025-08-04
Unclassified HIGH 8.3
CVE-2025-41659

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys.…

Mitigation only
Fix from $1,950 2025-08-04
Unclassified MEDIUM 5.5
CVE-2025-23285

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of…

Mitigation only
Fix from $1,600 2025-08-02
Langchain Chatglm Webui CRITICAL 9.8
CVE-2025-45150

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafte…

Mitigation only
Fix from $2,300 2025-08-01
Unclassified CRITICAL 10.0
CVE-2014-125121

Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combin…

Mitigation only
Fix from $2,300 2025-07-31
macOS MEDIUM 5.1
CVE-2025-43266

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…

Fix: 13.7.7 / 14.7.7+
Fix from $1,600 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43243

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
macOS MEDIUM 5.5
CVE-2025-43247

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…

Fix: 13.7.7 / 14.7.7+
Fix from $1,600 2025-07-30
Pacs Server CRITICAL 9.8
CVE-2025-26469

An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A …

Mitigation only
Fix from $2,300 2025-07-28
Unclassified CRITICAL 9.3
CVE-2017-20198

The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount conf…

No fix yet
Fix from $2,300 2025-07-23
Storage Scale MEDIUM 6.5
CVE-2025-36104

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions in…

Mitigation only
Fix from $1,600 2025-07-12
Unclassified MEDIUM 6.8
CVE-2023-39338

Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry polic…

Mitigation only
Fix from $1,600 2025-07-12
Junos HIGH 7.3
CVE-2025-30661

An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, lo…

Mitigation only
Fix from $1,950 2025-07-11
Apisix HIGH 7.8
CVE-2025-27446

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX…

Fix: after 0.5
Fix from $1,950 2025-07-06
Dpkg HIGH 8.2
CVE-2025-6297

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i…

Fix: 1.22.21+
Fix from $1,950 2025-07-01
Cloud Init MEDIUM 5.3
CVE-2024-11584

cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it…

Fix: 25.1.3+
Fix from $1,600 2025-06-26
Unclassified HIGH 7.0
CVE-2025-36537

Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on…

Mitigation only
Fix from $1,950 2025-06-24
Fastgpt CRITICAL 9.9
CVE-2025-49131

FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The …

Fix: 4.9.11+
Fix from $2,300 2025-06-09
Unclassified HIGH 7.3
CVE-2025-48961

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 3…

Mitigation only
Fix from $1,950 2025-06-04