Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-39005
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
Opnsense
23.7+
HIGH 7.5
CVE-2023-39003
OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
Opnsense
23.7+
HIGH 7.8
CVE-2022-39062
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product fo…
Sicam Toolbox Ii
07.10+
HIGH 7.3
CVE-2023-38497
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, d…
Cargo
0.72.2+
MEDIUM 5.4
CVE-2023-38991
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created…
Jeesite
No fix yet
HIGH 7.8
CVE-2023-20216
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevat…
Broadworks Application Delivery Platform
23.0.2023.05 / 24.0.2023.05+
HIGH 8.1
CVE-2023-3322
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…
Zenon
after 11.0.0
HIGH 7.8
CVE-2023-28133EPSS 6%
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
Endpoint Security
Mitigation only
HIGH 7.1
CVE-2023-33990
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with …
Sql Anywhere
Mitigation only
HIGH 7.3
CVE-2023-35870
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could interce…
S4core
Mitigation only
HIGH 7.5
CVE-2022-44719
An issue was discovered in Weblib Ucopia before 6.0.13. The SSH Server has Insecure Permissions.
Wireless Appliance Firmware
6.0.13+
HIGH 7.2
CVE-2023-37237
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arb…
Netbackup Appliance
4.1.0.1+
MEDIUM 5.5
CVE-2023-35799
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create a…
Endpoint Security
after 2.3.2
MEDIUM 6.5
CVE-2023-35168
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has …
Dataease
1.18.8+
HIGH 7.5
CVE-2023-29860
An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCo…
Taier
No fix yet
HIGH 7.5
CVE-2023-34981
A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header…
Tomcat
Mitigation only
HIGH 8.2
CVE-2023-34154
Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to cr…
Harmonyos
2.0+
MEDIUM 5.4
CVE-2023-34797
Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information.
Cwx
No fix yet
CRITICAL 9.8
CVE-2023-34852
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
Publiccms
after 4.0.202302
MEDIUM 5.5
CVE-2023-21142
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclos…
Android
Patch available
HIGH 8.1
CVE-2022-33163
IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifie…
Security Directory Suite Va
Patch available
MEDIUM 6.5
CVE-2023-35147
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attack…
Aws Codecommit Trigger
after 3.0.12
MEDIUM 5.3
CVE-2023-31142
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passe…
Discourse
3.0.4+
HIGH 7.1
CVE-2023-33695
Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/io/FileUti…
Hutool
after 5.8.17
HIGH 7.8
CVE-2023-30897
A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their ins…
Wincc
7.5.2.13+
MEDIUM 6.1
CVE-2023-2876
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (fi…
Rex640 Pcl1 Firmware
1.0.8 / 1.1.4+
HIGH 7.8
CVE-2023-28399
Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not …
Conprosys Hmi System
3.5.3+
HIGH 7.3
CVE-2023-28346
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints…
Insight
No fix yet
HIGH 8.8
CVE-2023-31874
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process').
Yank Note
No fix yet
HIGH 7.8
CVE-2023-31748
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.
Mobiletrans
No fix yet