Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Application Gateway MEDIUM 5.5
CVE-2024-45655

IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignme…

Fix: after 24.09
Fix from $1,600 2025-06-03
Universal Forwarder HIGH 8.0
CVE-2025-20298

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can resu…

Fix: 9.1.9 / 9.2.6+
Fix from $1,950 2025-06-02
Pcmanager HIGH 7.1
CVE-2025-2503

An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions…

Fix: 5.1.110.5082+
Fix from $1,950 2025-05-30
Directory Manager MEDIUM 5.0
CVE-2025-48747

Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment fo…

Fix: 11.1.25134.03+
Fix from $1,600 2025-05-28
Fess MEDIUM 5.5
CVE-2025-48382

Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates…

Fix: 14.19.2+
Fix from $1,600 2025-05-27
Unclassified MEDIUM 6.0
CVE-2025-46802

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

Mitigation only
Fix from $1,600 2025-05-26
Unclassified HIGH 8.5
CVE-2025-40672

A Privilege Escalation vulnerability has been found in Panloader component v3.24.0.0 by Espiral MS Group. This vulnerability allows any user to overr…

Mitigation only
Fix from $1,950 2025-05-26
Autodeploy Layer HIGH 8.8
CVE-2025-45472

Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.

Fix: after 1.2.0
Fix from $1,950 2025-05-22
Fc Stable Diffusion HIGH 8.8
CVE-2025-45468

Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.

Fix: after 1.0.18
Fix from $1,950 2025-05-22
Measure Cold Start HIGH 8.8
CVE-2025-45471

Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.

Fix: after 1.4.1
Fix from $1,950 2025-05-22
Checkmk MEDIUM 5.5
CVE-2025-32915

Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42…

Mitigation only
Fix from $1,600 2025-05-22
Niagara CRITICAL 9.8
CVE-2025-3944

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX a…

Mitigation only
Fix from $2,300 2025-05-22
Niagara CRITICAL 9.8
CVE-2025-3936

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on W…

Mitigation only
Fix from $2,300 2025-05-22
Gstreamer HIGH 7.8
CVE-2025-2759

GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges …

Fix: 1.25.1+
Fix from $1,950 2025-05-22
Unclassified HIGH 8.6
CVE-2025-34025

The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe defaul…

Mitigation only
Fix from $1,950 2025-05-21
Ipados MEDIUM 5.5
CVE-2025-31262

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visio…

Fix: 2.3 / 11.3+
Fix from $1,600 2025-05-19
Scalance Lpe9403 Firmware MEDIUM 5.5
CVE-2025-40572

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permi…

Mitigation only
Fix from $1,600 2025-05-13
Scalance Lpe9403 Firmware HIGH 7.8
CVE-2025-40574

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permi…

Mitigation only
Fix from $1,950 2025-05-13
Unclassified MEDIUM 5.9
CVE-2025-24009

A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected…

Mitigation only
Fix from $1,600 2025-05-13
Unclassified MEDIUM 6.6
CVE-2025-42997

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due …

Mitigation only
Fix from $1,600 2025-05-13
Unclassified HIGH 8.1
CVE-2025-26168

IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file t…

Mitigation only
Fix from $1,950 2025-05-07
Unclassified HIGH 8.1
CVE-2025-26169

IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that ca…

Mitigation only
Fix from $1,950 2025-05-07
Unclassified MEDIUM 5.5
CVE-2025-23245

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to access globa…

No fix yet
Fix from $1,600 2025-05-01
Automation Builder MEDIUM 5.5
CVE-2025-3395

Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue …

Fix: after 2.8.0
Fix from $1,600 2025-04-30
Automation Builder HIGH 7.8
CVE-2025-3394

Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

Fix: after 2.8.0
Fix from $1,950 2025-04-30
Unclassified MEDIUM 6.7
CVE-2025-30408

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor…

Mitigation only
Fix from $1,600 2025-04-24
Camera Station Pro HIGH 7.3
CVE-2025-0926

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a…

Fix: 6.8.43213+
Fix from $1,950 2025-04-23
Uos HIGH 7.8
CVE-2025-1731

An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V…

Fix: 1.32+
Fix from $1,950 2025-04-22
Unclassified MEDIUM 6.1
CVE-2025-0758

Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintend…

Mitigation only
Fix from $1,600 2025-04-16
User Management HIGH 7.5
CVE-2025-30708

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions that are a…

Fix: after 12.2.14
Fix from $1,950 2025-04-15