Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 5.3 CVE-2024-37087 The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service… Cloud Foundation 5.2+ Fix from $1,6002024-06-25 CRITICAL 9.8 CVE-2024-5163 Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks. No fix yet Fix from $2,3002024-06-17 HIGH 8.8 CVE-2024-37369 A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C… Factorytalk View 14.0+ Fix from $1,9502024-06-14 MEDIUM 6.8 CVE-2024-36821 Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root. Velop Whw0101 Firmware No fix yet Fix from $1,6002024-06-11 HIGH 8.8 CVE-2024-3668 The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due… Powerpack Addons For Elementor 2.10.18+ Fix from $1,9502024-06-08 HIGH 7.8 CVE-2024-30369 A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privi… Advanced Core Operating System Mitigation only Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-29078 Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated … Mitigation only Fix from $1,9502024-05-28 HIGH 8.1 CVE-2024-21902 An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploit… Qts Mitigation only Fix from $1,9502024-05-21 HIGH 7.8 CVE-2024-21835 Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalatio… Extreme Tuning Utility 7.14.0.15+ Fix from $1,9502024-05-16 HIGH 7.8 CVE-2023-5936 On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the syste… Mitigation only Fix from $1,9502024-05-15 MEDIUM 6.8 CVE-2024-27108 Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products No fix yet Fix from $1,6002024-05-14 CRITICAL 9.1 CVE-2024-33499 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278… Mitigation only Fix from $2,3002024-05-14 MEDIUM 6.3 CVE-2024-30208 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278… Mitigation only Fix from $1,6002024-05-14 HIGH 7.4 CVE-2024-1486 Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices Mitigation only Fix from $1,9502024-05-14 HIGH 7.8 CVE-2023-35841 Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of sys… Winflash 4.5.0.0+ Fix from $1,9502024-05-14 HIGH 7.8 CVE-2023-47712 IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions contr… Security Guardium Mitigation only Fix from $1,9502024-05-14 HIGH 7.8 CVE-2023-51579 Voltronic Power ViewPower Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca… Viewpower Mitigation only Fix from $1,9502024-05-03 HIGH 7.8 CVE-2023-40516 LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate priv… Simple Editor Mitigation only Fix from $1,9502024-05-03 MEDIUM 6.7 CVE-2024-24912 A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit … Harmony Endpoint Mitigation only Fix from $1,6002024-05-01 CRITICAL 9.8 CVE-2024-33435 Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback sy… Mitigation only Fix from $2,3002024-04-29 CRITICAL 9.4 CVE-2024-3375 Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained… Mitigation only Fix from $2,3002024-04-29 MEDIUM 6.2 CVE-2024-2905 A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit en… Mitigation only Fix from $1,6002024-04-25 MEDIUM 6.9 CVE-2024-32478 Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root ownership on installed files. Th… Patch available Fix from $1,6002024-04-19 MEDIUM 6.5 CVE-2024-29964 Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access t… Brocade Sannav 2.3.0a+ Fix from $1,6002024-04-19 HIGH 7.3 CVE-2024-24910 A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent f… Identity Agent 4.2.712+ Fix from $1,9502024-04-18 MEDIUM 6.1 CVE-2024-21063 Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle PeopleSoft (component: Benefits Administration). The suppo… Peoplesoft Enterprise Hcm Benefits Administration Mitigation only Fix from $1,6002024-04-16 MEDIUM 6.5 CVE-2024-25646 Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system informati… Businessobjects Web Intelligence Patch available Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2023-52554 Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. Emui Mitigation only Fix from $1,6002024-04-08 HIGH 7.5 CVE-2023-52388 Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability. Emui Mitigation only Fix from $1,9502024-04-08 HIGH 7.5 CVE-2023-52715 The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,9502024-04-07