Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.5 CVE-2023-39005 Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2. Opnsense 23.7+ Fix from $1,9502023-08-09 HIGH 7.5 CVE-2023-39003 OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp. Opnsense 23.7+ Fix from $1,9502023-08-09 HIGH 7.8 CVE-2022-39062 A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product fo… Sicam Toolbox Ii 07.10+ Fix from $1,9502023-08-08 HIGH 7.3 CVE-2023-38497 Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, d… Cargo 0.72.2+ Fix from $1,9502023-08-04 MEDIUM 5.4 CVE-2023-38991 An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created… Jeesite No fix yet Fix from $1,6002023-08-04 HIGH 7.8 CVE-2023-20216 A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevat… Broadworks Application Delivery Platform 23.0.2023.05 / 24.0.2023.05+ Fix from $1,9502023-08-03 HIGH 8.1 CVE-2023-3322 A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul… Zenon after 11.0.0 Fix from $1,9502023-07-24 HIGH 7.8 CVE-2023-28133EPSS 6% Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file Endpoint Security Mitigation only Fix from $1,9502023-07-23 HIGH 7.1 CVE-2023-33990 SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with … Sql Anywhere Mitigation only Fix from $1,9502023-07-11 HIGH 7.3 CVE-2023-35870 When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could interce… S4core Mitigation only Fix from $1,9502023-07-11 HIGH 7.5 CVE-2022-44719 An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions. Wireless Appliance Firmware 6.0.13+ Fix from $1,9502023-06-29 HIGH 7.2 CVE-2023-37237 In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arb… Netbackup Appliance 4.1.0.1+ Fix from $1,9502023-06-29 MEDIUM 5.5 CVE-2023-35799 Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create a… Endpoint Security after 2.3.2 Fix from $1,6002023-06-27 MEDIUM 6.5 CVE-2023-35168 DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has … Dataease 1.18.8+ Fix from $1,6002023-06-26 HIGH 7.5 CVE-2023-29860 An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCo… Taier No fix yet Fix from $1,9502023-06-23 HIGH 7.5 CVE-2023-34981 A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header… Tomcat Mitigation only Fix from $1,9502023-06-21 HIGH 8.2 CVE-2023-34154 Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to cr… Harmonyos 2.0+ Fix from $1,9502023-06-16 MEDIUM 5.4 CVE-2023-34797 Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information. Cwx No fix yet Fix from $1,6002023-06-15 CRITICAL 9.8 CVE-2023-34852 PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions. Publiccms after 4.0.202302 Fix from $2,3002023-06-15 MEDIUM 5.5 CVE-2023-21142 In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclos… Android Patch available Fix from $1,6002023-06-15 HIGH 8.1 CVE-2022-33163 IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifie… Security Directory Suite Va Patch available Fix from $1,9502023-06-15 MEDIUM 6.5 CVE-2023-35147 Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attack… Aws Codecommit Trigger after 3.0.12 Fix from $1,6002023-06-14 MEDIUM 5.3 CVE-2023-31142 Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passe… Discourse 3.0.4+ Fix from $1,6002023-06-13 HIGH 7.1 CVE-2023-33695 Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/io/FileUti… Hutool after 5.8.17 Fix from $1,9502023-06-13 HIGH 7.8 CVE-2023-30897 A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their ins… Wincc 7.5.2.13+ Fix from $1,9502023-06-13 MEDIUM 6.1 CVE-2023-2876 Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (fi… Rex640 Pcl1 Firmware 1.0.8 / 1.1.4+ Fix from $1,6002023-06-13 HIGH 7.8 CVE-2023-28399 Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not … Conprosys Hmi System 3.5.3+ Fix from $1,9502023-06-01 HIGH 7.3 CVE-2023-28346 An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints… Insight No fix yet Fix from $1,9502023-05-31 HIGH 8.8 CVE-2023-31874 Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process'). Yank Note No fix yet Fix from $1,9502023-05-29 HIGH 7.8 CVE-2023-31748 Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file. Mobiletrans No fix yet Fix from $1,9502023-05-24