Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 6.0 CVE-2025-21551 Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploi… Solaris Mitigation only Fix from $1,6002025-01-21 HIGH 7.5 CVE-2025-0590 Improper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk. Mitigation only Fix from $1,9502025-01-20 CRITICAL 9.1 CVE-2024-38337 IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker to retrieve or alter sensitiv… Sterling Secure Proxy 6.0.3.1+ Fix from $2,3002025-01-19 MEDIUM 6.7 CVE-2024-51448 IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files i… Robotic Process Automation after 23.0.18 Fix from $1,6002025-01-18 HIGH 7.8 CVE-2025-21325 Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19044.5371 / 10.0.19045.5371+ Fix from $1,9502025-01-17 MEDIUM 6.5 CVE-2024-39967 Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command. Mitigation only Fix from $1,6002025-01-15 HIGH 8.8 CVE-2024-11497 An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access. No fix yet Fix from $1,9502025-01-14 HIGH 8.8 CVE-2025-0066 Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted infor… Sap Basis Patch available Fix from $1,9502025-01-14 MEDIUM 5.5 CVE-2023-38037 ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user… Mitigation only Fix from $1,6002025-01-09 HIGH 8.8 CVE-2024-55411 An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying c… Mitigation only Fix from $1,9502025-01-07 CRITICAL 9.1 CVE-2024-53931 The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) … Mitigation only Fix from $2,3002025-01-06 CRITICAL 9.1 CVE-2024-53932 The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any app… Mitigation only Fix from $2,3002025-01-06 MEDIUM 5.5 CVE-2024-47475 Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticate… Powerscale Onefs 9.4.0.20+ Fix from $1,6002025-01-06 MEDIUM 5.5 CVE-2024-49385 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 4… Mitigation only Fix from $1,6002025-01-02 HIGH 7.3 CVE-2024-55955 An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow … Deep Security Agent Mitigation only Fix from $1,9502024-12-31 HIGH 7.6 CVE-2024-45497 A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /va… Mitigation only Fix from $1,9502024-12-31 MEDIUM 6.8 CVE-2024-47104 IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the… I Mitigation only Fix from $1,6002024-12-18 MEDIUM 6.9 CVE-2024-12564 Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installi… Mitigation only Fix from $1,6002024-12-12 MEDIUM 5.3 CVE-2024-12255 The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 … Accept Stripe Payments Using Contact Form 7 2.6+ Fix from $1,6002024-12-12 HIGH 7.1 CVE-2024-12363 Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to … Mitigation only Fix from $1,9502024-12-11 HIGH 7.1 CVE-2024-7572 Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files. Desktop \& Server Management 2024.3.5740+ Fix from $1,9502024-12-10 MEDIUM 5.5 CVE-2024-8540 Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive applicatio… Standalone Sentry 9.20.2+ Fix from $1,6002024-12-10 HIGH 7.1 CVE-2024-10256 Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. Endpoint Manager 9.7.703 / 2024.4+ Fix from $1,9502024-12-10 MEDIUM 5.9 CVE-2024-8256 In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to … Mitigation only Fix from $1,6002024-12-10 CRITICAL 9.8 CVE-2024-41647 Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code… Robot Operating System Patch available Fix from $2,3002024-12-06 HIGH 7.8 CVE-2024-11220 A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the se… Open Automation Software 20.0.0.76+ Fix from $1,9502024-12-06 MEDIUM 6.5 CVE-2024-45841 Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earl… Mitigation only Fix from $1,6002024-12-05 HIGH 8.1 CVE-2024-12149 Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allow… Remote Desktop Manager 2024.3.20.0+ Fix from $1,9502024-12-04 MEDIUM 5.0 CVE-2024-12151 Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permissio… Devolutions Server 2024.3.9.0+ Fix from $1,6002024-12-04 HIGH 8.2 CVE-2024-37574 The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without use… Mitigation only Fix from $1,9502024-12-04