Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.0
CVE-2025-21551
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploi…
Solaris
Mitigation only
HIGH 7.5
CVE-2025-0590
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to
information leakage risk.
Mitigation only
CRITICAL 9.1
CVE-2024-38337
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv…
Sterling Secure Proxy
6.0.3.1+
MEDIUM 6.7
CVE-2024-51448
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files i…
Robotic Process Automation
after 23.0.18
HIGH 7.8
CVE-2025-21325
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Windows 10 21h2
10.0.19044.5371 / 10.0.19045.5371+
MEDIUM 6.5
CVE-2024-39967
Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.
Mitigation only
HIGH 8.8
CVE-2024-11497
An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.
No fix yet
HIGH 8.8
CVE-2025-0066
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted infor…
Sap Basis
Patch available
MEDIUM 5.5
CVE-2023-38037
ActiveSupport::EncryptedFile writes contents that will be encrypted to a
temporary file. The temporary file's permissions are defaulted to the user…
Mitigation only
HIGH 8.8
CVE-2024-55411
An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying c…
Mitigation only
CRITICAL 9.1
CVE-2024-53931
The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) …
Mitigation only
CRITICAL 9.1
CVE-2024-53932
The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any app…
Mitigation only
MEDIUM 5.5
CVE-2024-47475
Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticate…
Powerscale Onefs
9.4.0.20+
MEDIUM 5.5
CVE-2024-49385
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 4…
Mitigation only
HIGH 7.3
CVE-2024-55955
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow …
Deep Security Agent
Mitigation only
HIGH 7.6
CVE-2024-45497
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /va…
Mitigation only
MEDIUM 6.8
CVE-2024-47104
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the…
I
Mitigation only
MEDIUM 6.9
CVE-2024-12564
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installi…
Mitigation only
MEDIUM 5.3
CVE-2024-12255
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 …
Accept Stripe Payments Using Contact Form 7
2.6+
HIGH 7.1
CVE-2024-12363
Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to …
Mitigation only
HIGH 7.1
CVE-2024-7572
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
Desktop \& Server Management
2024.3.5740+
MEDIUM 5.5
CVE-2024-8540
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive applicatio…
Standalone Sentry
9.20.2+
HIGH 7.1
CVE-2024-10256
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Endpoint Manager
9.7.703 / 2024.4+
MEDIUM 5.9
CVE-2024-8256
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to …
Mitigation only
CRITICAL 9.8
CVE-2024-41647
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…
Robot Operating System
Patch available
HIGH 7.8
CVE-2024-11220
A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the se…
Open Automation Software
20.0.0.76+
MEDIUM 6.5
CVE-2024-45841
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earl…
Mitigation only
HIGH 8.1
CVE-2024-12149
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allow…
Remote Desktop Manager
2024.3.20.0+
MEDIUM 5.0
CVE-2024-12151
Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permissio…
Devolutions Server
2024.3.9.0+
HIGH 8.2
CVE-2024-37574
The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without use…
Mitigation only