Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
CRITICAL 9.8 CVE-2024-9142 External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allo… Mitigation only Fix from $2,3002024-09-25 HIGH 7.5 CVE-2022-43845 IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag.… Aspera Console 3.4.5+ Fix from $1,9502024-09-25 HIGH 7.5 CVE-2024-8900 An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability… Firefox 129.0+ Fix from $1,9502024-09-17 CRITICAL 9.8 CVE-2024-8039 Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover ri… Mitigation only Fix from $2,3002024-09-14 HIGH 7.8 CVE-2024-6510 Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijackin… Internet Security 24.1+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-41171 A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions… Mitigation only Fix from $1,9502024-09-10 HIGH 8.8 CVE-2024-45041 External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called d… External Secrets Operator 0.10.2+ Fix from $1,9502024-09-09 HIGH 7.8 CVE-2024-38456 HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerabilit… Mitigation only Fix from $1,9502024-09-03 MEDIUM 5.5 CVE-2023-49582 Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pot… Portable Runtime 1.7.5+ Fix from $1,6002024-08-26 HIGH 8.1 CVE-2022-43915 IBM App Connect Enterprise Certified Container 5.0, 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.… App Connect Enterprise Certified Container Mitigation only Fix from $1,9502024-08-24 HIGH 7.5 CVE-2024-7986 A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat acto… Thinmanager 11.1.8 / 11.2.9+ Fix from $1,9502024-08-23 HIGH 7.8 CVE-2024-5930 VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala… Advanced Security Mitigation only Fix from $1,9502024-08-21 HIGH 8.8 CVE-2024-7513 CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permission… Factorytalk View Mitigation only Fix from $1,9502024-08-14 HIGH 7.8 CVE-2024-5915 A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs wit… Globalprotect 6.1.5 / 6.2.4+ Fix from $1,9502024-08-14 HIGH 7.8 CVE-2024-25561 Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potent… Hid Event Filter Driver 2.2.2.1+ Fix from $1,9502024-08-14 HIGH 7.8 CVE-2024-23908 Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to… Flexlm License Daemons For Intel Fpga 11.19.5.0+ Fix from $1,9502024-08-14 HIGH 8.5 CVE-2024-6619 In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and … Mitigation only Fix from $1,9502024-08-13 HIGH 7.8 CVE-2024-43199 Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user. Ndoutils 2.1.4+ Fix from $1,9502024-08-07 MEDIUM 6.0 CVE-2024-41820 Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. I… Patch available Fix from $1,6002024-08-05 HIGH 8.0 CVE-2024-41720 Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a networ… Zwx 2000csw2 Hn Firmware 0.3.15+ Fix from $1,9502024-08-05 HIGH 7.8 CVE-2024-41954 FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fog… Fogproject after 1.5.10.41 Fix from $1,9502024-07-31 HIGH 7.8 CVE-2024-31202 A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local… Thermoscan Ip Mitigation only Fix from $1,9502024-07-31 HIGH 7.5 CVE-2022-33167 IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive informa… Security Directory Integrator Mitigation only Fix from $1,9502024-07-30 HIGH 7.5 CVE-2024-41685 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web… Sy Gpon 1110 Wdont Firmware Mitigation only Fix from $1,9502024-07-26 HIGH 8.2 CVE-2024-1724 In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. … Snapd 2.62+ Fix from $1,9502024-07-25 CRITICAL 9.9 CVE-2024-5618 Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionali… Mitigation only Fix from $2,3002024-07-18 HIGH 8.8 CVE-2024-6435 A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions whi… Pavilion8 Mitigation only Fix from $1,9502024-07-16 MEDIUM 6.1 CVE-2024-6739 The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal t… Mailaudit 6.1.7.040+ Fix from $1,6002024-07-15 MEDIUM 6.7 CVE-2024-20456 A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Se… Ios Xr Mitigation only Fix from $1,6002024-07-10 HIGH 7.8 CVE-2024-28827 Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a loca… Checkmk after 2.0.0 Fix from $1,9502024-07-10