Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.5 CVE-2024-30413 Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect avail… Emui No fix yet Fix from $1,9502024-04-07 MEDIUM 6.5 CVE-2024-3250 It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged … Pebble 1.4.1 / 1.7.3+ Fix from $1,6002024-04-04 MEDIUM 6.7 CVE-2024-28589 An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary cod… Mitigation only Fix from $1,6002024-04-03 MEDIUM 5.5 CVE-2024-25956 Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentia… Grab 5.0.5+ Fix from $1,6002024-03-26 HIGH 7.3 CVE-2024-29187 WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses Ge… Patch available Fix from $1,9502024-03-24 MEDIUM 6.7 CVE-2024-21431 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability Windows 10 21h2 10.0.19044.4170 / 10.0.19045.4170+ Fix from $1,6002024-03-12 MEDIUM 5.3 CVE-2024-28163 Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which… Netweaver Process Integration Mitigation only Fix from $1,6002024-03-12 MEDIUM 5.3 CVE-2024-25644 Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low… Netweaver Mitigation only Fix from $1,6002024-03-12 MEDIUM 5.3 CVE-2024-25645 Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted… Netweaver Enterprise Portal No fix yet Fix from $1,6002024-03-12 HIGH 7.8 CVE-2024-27294 dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ow… Dp Golang 1.2.7+ Fix from $1,9502024-02-29 MEDIUM 5.0 CVE-2024-0019 In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a miss… Android Patch available Fix from $1,6002024-02-16 HIGH 8.8 CVE-2024-21915 A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic us… Factorytalk Services Platform 2.74+ Fix from $1,9502024-02-16 HIGH 7.8 CVE-2023-33870 Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable esca… Administrative Tools For Intel Network Adapters 28.2+ Fix from $1,9502024-02-14 MEDIUM 5.3 CVE-2024-24740 SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64U… Netweaver Application Server Abap Mitigation only Fix from $1,6002024-02-13 HIGH 7.5 CVE-2023-50292 Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This iss… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 MEDIUM 5.5 CVE-2023-34042 The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by a… Spring Security 5.8.7 / 6.0.7+ Fix from $1,6002024-02-05 HIGH 8.1 CVE-2023-47564 An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability cou… Qsync Central 4.3.0.11 / 4.4.0.15+ Fix from $1,9502024-02-02 HIGH 8.8 CVE-2020-24681 Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This i… Automation Studio 4.7.7.74 / 4.8.6.30+ Fix from $1,9502024-02-02 HIGH 7.8 CVE-2024-22016 In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow pri… Rapid Scada after 5.8.4 Fix from $1,9502024-02-02 MEDIUM 5.5 CVE-2024-22236 In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnera… Spring Cloud Contract 3.1.10 / 4.0.5+ Fix from $1,6002024-01-31 MEDIUM 6.2 CVE-2024-23223 A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS… Ipados 10.3 / 14.3+ Fix from $1,6002024-01-23 HIGH 7.8 CVE-2023-38541 Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2… Hid Event Filter Driver after 2.2.2.1 Fix from $1,9502024-01-19 HIGH 7.5 CVE-2023-52116 Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exception… Emui Mitigation only Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-52107 Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confiden… Emui Mitigation only Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2020-36770 pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem… Ebuild For Slurm after 22.05.3 Fix from $2,3002024-01-15 HIGH 8.8 CVE-2023-49257 An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privi… H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 HIGH 7.8 CVE-2023-44120 A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administr… Spectrum Power 7 23q4+ Fix from $1,9502024-01-09 HIGH 7.8 CVE-2023-41776 There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to es… Zxcloud Irai 7.23.32+ Fix from $1,9502024-01-03 MEDIUM 5.4 CVE-2023-7055 A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /… Online Notes Sharing System No fix yet Fix from $1,6002023-12-22 CRITICAL 9.8 CVE-2023-0757 Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unaut… Multiprog Mitigation only Fix from $2,3002023-12-14