Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.1 CVE-2024-42449EPSS 6% From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary fil… Mitigation only Fix from $1,9502024-12-04 MEDIUM 6.4 CVE-2024-21703 This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows install… Confluence Data Center 7.19.18 / 8.5.5+ Fix from $1,6002024-11-27 MEDIUM 5.9 CVE-2024-28955 Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredu… Mitigation only Fix from $1,6002024-11-26 HIGH 7.8 CVE-2024-9244 Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers t… Pdf Editor after 2024.2.3.25184 Fix from $1,9502024-11-22 HIGH 7.8 CVE-2024-9245 Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers t… Pdf Editor after 2024.2.3.25184 Fix from $1,9502024-11-22 HIGH 7.8 CVE-2024-7245 Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala… Panda Dome Mitigation only Fix from $1,9502024-11-22 HIGH 7.8 CVE-2024-6871 G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate… Total Security Mitigation only Fix from $1,9502024-11-22 MEDIUM 6.0 CVE-2024-38646 An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability c… Notes Station 3 3.9.7+ Fix from $1,6002024-11-22 MEDIUM 5.3 CVE-2024-11176 Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorre… Mitigation only Fix from $1,6002024-11-20 HIGH 7.1 CVE-2024-41974 A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lea… Mitigation only Fix from $1,9502024-11-18 MEDIUM 5.7 CVE-2024-41970 A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources. Mitigation only Fix from $1,6002024-11-18 HIGH 7.8 CVE-2024-36294 Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalati… Driver \& Support Assistant 24.3.26.8+ Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-36276 Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalati… Computing Improvement Program 2.4.10852+ Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-39709 Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (N… Connect Secure 9.1 / 22.6+ Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-47783 A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation f… Siport 3.4.0+ Fix from $1,9502024-11-12 MEDIUM 6.5 CVE-2024-47808 A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not prop… Sinec Nms 3.0+ Fix from $1,6002024-11-12 HIGH 7.8 CVE-2024-50590 Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one o… Mitigation only Fix from $1,9502024-11-08 HIGH 8.6 CVE-2024-10526 Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL per… Mitigation only Fix from $1,9502024-11-07 HIGH 7.1 CVE-2024-45164 Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Po… Secure Internet Access Enterprise Threatavert No fix yet Fix from $1,9502024-11-04 HIGH 7.1 CVE-2024-0128 NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful … Mitigation only Fix from $1,9502024-10-26 HIGH 7.5 CVE-2022-30354 OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is req… Ovaledge 5.2.9+ Fix from $1,9502024-10-25 HIGH 7.3 CVE-2023-6729 Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low… Mitigation only Fix from $1,9502024-10-17 HIGH 7.8 CVE-2024-22029 Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root Mitigation only Fix from $1,9502024-10-16 CRITICAL 9.8 CVE-2024-10018 Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component. Mitigation only Fix from $2,3002024-10-16 HIGH 7.5 CVE-2024-44729 Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privi… Mitigation only Fix from $1,9502024-10-11 MEDIUM 6.5 CVE-2024-47833 Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected v… Taipy 4.0.0+ Fix from $1,6002024-10-09 HIGH 7.8 CVE-2024-7612 Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components. Endpoint Manager Mobile 12.0.0.5 / 12.1.0.4+ Fix from $1,9502024-10-08 CRITICAL 9.8 CVE-2024-24117 Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login … Rg Nbs2009g P Firmware No fix yet Fix from $2,3002024-10-02 CRITICAL 9.8 CVE-2024-6360 Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized acces… Vertica 12.0.4-30 / 23.3.0-11+ Fix from $2,3002024-10-02 HIGH 8.8 CVE-2024-7594 Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields o… Vault 1.15.15 / 1.16.10+ Fix from $1,9502024-09-26