Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2023-40361
SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privile…
Qiata
No fix yet
HIGH 7.5
CVE-2023-34437
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a vulnerability in their password retrieval functionality which could a…
Bentley Nevada 3500 System Firmware
Mitigation only
MEDIUM 5.5
CVE-2023-44201
An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a …
Junos
20.4+
CRITICAL 9.1
CVE-2023-32723
Request to LDAP is sent before user permissions are checked.
Zabbix
4.0.19 / 4.4.7+
HIGH 8.8
CVE-2023-32724
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
Zabbix
after 6.4.5
HIGH 7.8
CVE-2023-45205
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and f…
Sicam Pas\/pqs
8.20+
HIGH 7.8
CVE-2022-30527
A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders c…
Sinec Nms
2.0+
HIGH 7.5
CVE-2023-42189
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip …
Mini Smart Wi Fi Plug Firmware
Mitigation only
MEDIUM 5.3
CVE-2023-45364
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision exis…
Debian Linux
1.39.5+
HIGH 7.1
CVE-2023-36465
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…
Decidim
0.26.8 / 0.27.4+
MEDIUM 6.5
CVE-2023-44387
Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle…
Gradle
7.6.3 / 8.4.0+
HIGH 7.5
CVE-2023-5077
The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating …
Vault
1.13.0+
HIGH 8.8
CVE-2023-20254
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attac…
Sd Wan Manager
20.6.3.4 / 20.9.3.2+
MEDIUM 5.3
CVE-2023-4565
Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be…
Emui
Mitigation only
MEDIUM 5.3
CVE-2023-41295
Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to tu…
Emui
Mitigation only
HIGH 8.8
CVE-2023-4665
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.
This issue affects Saphira Connect: b…
Connect
9.0+
HIGH 7.8
CVE-2023-38557
A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update scr…
Spectrum Power 7
23q3+
CRITICAL 9.9
CVE-2023-40622
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attack…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.3
CVE-2023-32005
A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used…
Node.js
20.5.1+
HIGH 7.8
CVE-2023-32162
Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca…
Driver
Mitigation only
HIGH 7.2
CVE-2023-3915
An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all…
GitLab
16.1.5 / 16.2.5+
MEDIUM 5.5
CVE-2023-34391
Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/M…
Sel 5033 Acselerator Real Time Automation Controller
1.35.151.21000+
HIGH 8.8
CVE-2023-40754
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attacker…
Car Rental Script
Mitigation only
MEDIUM 6.3
CVE-2023-20200
A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security…
Firepower 9300 Firmware
4.1 / 4.2+
MEDIUM 5.4
CVE-2023-20230
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenti…
Application Policy Infrastructure Controller
5.2 / 6.0+
MEDIUM 6.0
CVE-2023-20234
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesyst…
Firepower Extensible Operating System
Mitigation only
HIGH 7.8
CVE-2023-4383
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file…
Escan Anti Virus
No fix yet
HIGH 7.5
CVE-2023-4332
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
Raid Controller Web Interface
Mitigation only
HIGH 7.8
CVE-2023-28658
Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalatio…
Oneapi Math Kernel Library
2022.0+
CRITICAL 9.8
CVE-2023-39004
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attac…
Opnsense
23.7+