Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.8 CVE-2023-49257 An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privi… H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 HIGH 7.8 CVE-2023-44120 A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local administr… Spectrum Power 7 23q4+ Fix from $1,9502024-01-09 HIGH 7.8 CVE-2023-41776 There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to es… Zxcloud Irai 7.23.32+ Fix from $1,9502024-01-03 MEDIUM 5.4 CVE-2023-7055 A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /… Online Notes Sharing System No fix yet Fix from $1,6002023-12-22 CRITICAL 9.8 CVE-2023-0757 Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unaut… Multiprog Mitigation only Fix from $2,3002023-12-14 CRITICAL 9.8 CVE-2023-46141 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthen… Automationworx Software Suite Mitigation only Fix from $2,3002023-12-14 HIGH 8.8 CVE-2023-46142 A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full … Axc F 1152 Firmware after 2024.0 Fix from $1,9502023-12-14 HIGH 7.8 CVE-2023-25648 There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileg… Zxcloud Irai 7.23.21+ Fix from $1,9502023-12-14 CRITICAL 9.8 CVE-2023-6593 Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the applicati… Remote Desktop Manager 2023.3.5.0+ Fix from $2,3002023-12-12 HIGH 7.3 CVE-2023-49580 SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to … Graphical User Interface Mitigation only Fix from $1,9502023-12-12 MEDIUM 5.5 CVE-2023-42924 A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app may be able to access sensit… macOS 13.6.3 / 14.2+ Fix from $1,6002023-12-12 HIGH 7.8 CVE-2023-50446 An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow any local unprivileged user to … Mullvad Vpn after 2023.5 Fix from $1,9502023-12-10 HIGH 7.8 CVE-2023-49797 PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application, elevated as a privileged pr… Pyinstaller 5.13.1+ Fix from $1,9502023-12-09 CRITICAL 9.1 CVE-2023-40302 NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability Ngeniuspulse Mitigation only Fix from $2,3002023-12-07 CRITICAL 9.1 CVE-2023-49946 In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This al… Forgejo 1.20.5-1+ Fix from $2,3002023-12-03 MEDIUM 5.4 CVE-2023-5651 The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be del… Wp Hotel Booking 2.0.8+ Fix from $1,6002023-11-20 HIGH 7.8 CVE-2023-6179 Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker cou… Prowatch Mitigation only Fix from $1,9502023-11-17 MEDIUM 5.4 CVE-2023-48087 xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat. Xxl Job No fix yet Fix from $1,6002023-11-15 HIGH 7.8 CVE-2023-39230 Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potent… Rapid Storage Technology 16.8.5.1014.9+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-34997 Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated… Server Configuration Utility 16.0.9+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-34314 Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable … Simics Simulator 1.7.2+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2022-41700 Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user t… Nuc Pro Software Suite 2.0.0.9+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2022-33898 Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated user to p… Nuc Watchdog Timer Utility 2.0.21.0+ Fix from $1,9502023-11-14 MEDIUM 5.4 CVE-2023-36633 An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker … Fortimail 7.0.6 / 7.2.3+ Fix from $1,6002023-11-14 HIGH 7.8 CVE-2023-28134 Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first o… Endpoint Security No fix yet Fix from $1,9502023-11-12 MEDIUM 6.7 CVE-2023-3282 A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a … Cortex Xsoar 6.10.0+ Fix from $1,6002023-11-08 MEDIUM 5.5 CVE-2023-5136 An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulne… Topografix Data Plugin Mitigation only Fix from $1,6002023-11-08 HIGH 8.8 CVE-2023-46449 Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the pass… Inventory Management System No fix yet Fix from $1,9502023-10-26 MEDIUM 6.5 CVE-2023-42861 A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's… macOS 14.1+ Fix from $1,6002023-10-25 CRITICAL 9.8 CVE-2023-42489 EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource Eisbaer Scada after 3.0.6433.1964 Fix from $2,3002023-10-25