Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-30413
Vulnerability of improper permission control in the window management module.
Impact: Successful exploitation of this vulnerability will affect avail…
Emui
No fix yet
MEDIUM 6.5
CVE-2024-3250
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged …
Pebble
1.4.1 / 1.7.3+
MEDIUM 6.7
CVE-2024-28589
An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary cod…
Mitigation only
MEDIUM 5.5
CVE-2024-25956
Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentia…
Grab
5.0.5+
HIGH 7.3
CVE-2024-29187
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses Ge…
Patch available
MEDIUM 6.7
CVE-2024-21431
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Windows 10 21h2
10.0.19044.4170 / 10.0.19045.4170+
MEDIUM 5.3
CVE-2024-28163
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which…
Netweaver Process Integration
Mitigation only
MEDIUM 5.3
CVE-2024-25644
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low…
Netweaver
Mitigation only
MEDIUM 5.3
CVE-2024-25645
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted…
Netweaver Enterprise Portal
No fix yet
HIGH 7.8
CVE-2024-27294
dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ow…
Dp Golang
1.2.7+
MEDIUM 5.0
CVE-2024-0019
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due to a miss…
Android
Patch available
HIGH 8.8
CVE-2024-21915
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic us…
Factorytalk Services Platform
2.74+
HIGH 7.8
CVE-2023-33870
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable esca…
Administrative Tools For Intel Network Adapters
28.2+
MEDIUM 5.3
CVE-2024-24740
SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64U…
Netweaver Application Server Abap
Mitigation only
HIGH 7.5
CVE-2023-50292
Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr.
This iss…
Solr
8.11.3 / 9.4.1+
MEDIUM 5.5
CVE-2023-34042
The spring-security.xsd file inside the
spring-security-config jar is world writable which means that if it were
extracted it could be written by a…
Spring Security
5.8.7 / 6.0.7+
HIGH 8.1
CVE-2023-47564
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability cou…
Qsync Central
4.3.0.11 / 4.4.0.15+
HIGH 8.8
CVE-2020-24681
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This i…
Automation Studio
4.7.7.74 / 4.8.6.30+
HIGH 7.8
CVE-2024-22016
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow pri…
Rapid Scada
after 5.8.4
MEDIUM 5.5
CVE-2024-22236
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnera…
Spring Cloud Contract
3.1.10 / 4.0.5+
MEDIUM 6.2
CVE-2024-23223
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS…
Ipados
10.3 / 14.3+
HIGH 7.8
CVE-2023-38541
Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2…
Hid Event Filter Driver
after 2.2.2.1
HIGH 7.5
CVE-2023-52116
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exception…
Emui
Mitigation only
HIGH 7.5
CVE-2023-52107
Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confiden…
Emui
Mitigation only
CRITICAL 9.8
CVE-2020-36770
pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem…
Ebuild For Slurm
after 22.05.3
HIGH 8.8
CVE-2023-49257
An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privi…
H8951 4g Esp Firmware
2310271149+
HIGH 7.8
CVE-2023-44120
A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administr…
Spectrum Power 7
23q4+
HIGH 7.8
CVE-2023-41776
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to es…
Zxcloud Irai
7.23.32+
MEDIUM 5.4
CVE-2023-7055
A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /…
Online Notes Sharing System
No fix yet
CRITICAL 9.8
CVE-2023-0757
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unaut…
Multiprog
Mitigation only