Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.5 CVE-2026-50602 A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 b… Fix unknown Fix from $4,9002026-08-17 HIGH 8.6 CVE-2026-73664 FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.9 CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-50544 NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default ins… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.8 CVE-2026-65940 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. No fix yet Fix from $4,0002026-08-12 HIGH 7.8 CVE-2026-14478 A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC mess… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.5 CVE-2026-48790 Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `s… No fix yet Fix from $4,0002026-08-11 HIGH 7.0 CVE-2025-0046 Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution. No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-63522 Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. Azure Sql Database No fix yet Fix from $4,9002026-08-11 MEDIUM 6.0 CVE-2026-69108 A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privileg… No fix yet Fix from $4,0002026-08-11 HIGH 7.2 CVE-2026-4757 A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-63623 A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.2 CVE-2026-15430 Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged … No fix yet Fix from $1,6002026-08-03 MEDIUM 5.5 CVE-2026-68563 A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data`… No fix yet Fix from $1,6002026-07-30 CRITICAL 9.3 CVE-2026-48499 Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut… No fix yet Fix from $2,3002026-07-30 MEDIUM 5.5 CVE-2026-64707 A permissions issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Se… Ipados 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 HIGH 8.8 CVE-2026-61892 Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. No fix yet Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-16157 Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside… No fix yet Fix from $1,9502026-07-22 MEDIUM 6.3 CVE-2026-62519 Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Supported versions that are affecte… E Business Suite after 12.2.15 Fix from $1,6002026-07-21 CRITICAL 9.4 CVE-2026-61186 Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is af… Agile Engineering Data Management No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-61155 Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is a… Commerce Guided Search Platform Services No fix yet Fix from $2,3002026-07-21 HIGH 7.1 CVE-2026-60659 Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily expl… Solaris No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-63358 FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' functio… Filegator 7.14.2+ Fix from $1,9502026-07-21 HIGH 7.2 CVE-2026-44878 A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the … No fix yet Fix from $1,9502026-07-21 MEDIUM 5.5 CVE-2026-65065 Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The se… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.2 CVE-2026-64613 Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created … No fix yet Fix from $1,6002026-07-21 MEDIUM 6.9 CVE-2026-47134 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk p… No fix yet Fix from $1,6002026-07-20 HIGH 8.8 CVE-2026-49445 Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embe… Cilium 1.17.14 / 1.18.8+ Fix from $1,9502026-07-15 MEDIUM 6.1 CVE-2026-15779 A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the pat… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.1 CVE-2026-53486 The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di… Mitigation only Fix from $2,3002026-07-14