Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2024-37087
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service…
Cloud Foundation
5.2+
CRITICAL 9.8
CVE-2024-5163
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
No fix yet
HIGH 8.8
CVE-2024-37369
A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C…
Factorytalk View
14.0+
MEDIUM 6.8
CVE-2024-36821
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
Velop Whw0101 Firmware
No fix yet
HIGH 8.8
CVE-2024-3668
The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due…
Powerpack Addons For Elementor
2.10.18+
HIGH 7.8
CVE-2024-30369
A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privi…
Advanced Core Operating System
Mitigation only
HIGH 7.5
CVE-2024-29078
Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated …
Mitigation only
HIGH 8.1
CVE-2024-21902
An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploit…
Qts
Mitigation only
HIGH 7.8
CVE-2024-21835
Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalatio…
Extreme Tuning Utility
7.14.0.15+
HIGH 7.8
CVE-2023-5936
On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges.
By tampering with such file, a malicious local user in the syste…
Mitigation only
MEDIUM 6.8
CVE-2024-27108
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
No fix yet
CRITICAL 9.1
CVE-2024-33499
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…
Mitigation only
MEDIUM 6.3
CVE-2024-30208
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…
Mitigation only
HIGH 7.4
CVE-2024-1486
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
Mitigation only
HIGH 7.8
CVE-2023-35841
Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of sys…
Winflash
4.5.0.0+
HIGH 7.8
CVE-2023-47712
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr…
Security Guardium
Mitigation only
HIGH 7.8
CVE-2023-51579
Voltronic Power ViewPower Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca…
Viewpower
Mitigation only
HIGH 7.8
CVE-2023-40516
LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate priv…
Simple Editor
Mitigation only
MEDIUM 6.7
CVE-2024-24912
A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit …
Harmony Endpoint
Mitigation only
CRITICAL 9.8
CVE-2024-33435
Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback sy…
Mitigation only
CRITICAL 9.4
CVE-2024-3375
Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained…
Mitigation only
MEDIUM 6.2
CVE-2024-2905
A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit en…
Mitigation only
MEDIUM 6.9
CVE-2024-32478
Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. Th…
Patch available
MEDIUM 6.5
CVE-2024-29964
Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access t…
Brocade Sannav
2.3.0a+
HIGH 7.3
CVE-2024-24910
A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent f…
Identity Agent
4.2.712+
MEDIUM 6.1
CVE-2024-21063
Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The suppo…
Peoplesoft Enterprise Hcm Benefits Administration
Mitigation only
MEDIUM 6.5
CVE-2024-25646
Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system informati…
Businessobjects Web Intelligence
Patch available
MEDIUM 6.5
CVE-2023-52554
Permission control vulnerability in the Bluetooth module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Emui
Mitigation only
HIGH 7.5
CVE-2023-52388
Permission control vulnerability in the clock module.
Impact: Successful exploitation of this vulnerability will affect availability.
Emui
Mitigation only
HIGH 7.5
CVE-2023-52715
The SystemUI module has a vulnerability in permission management.
Impact: Successful exploitation of this vulnerability may affect availability.
Harmonyos
No fix yet