Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.5 CVE-2026-9789 A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P… Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.3 CVE-2026-2254 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain… Vantara Pentaho Data Integration And Analytics 10.2.0.7 / 11.0.0.0+ Fix from $1,6002026-05-27 MEDIUM 5.5 CVE-2025-43290 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app … macOS 14.8 / 15.7+ Fix from $1,6002026-05-26 HIGH 7.8 CVE-2026-25112 A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack. No fix yet Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-42497 Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() pas… \ 3.08+ Fix from $1,9502026-05-26 HIGH 8.5 CVE-2026-9489 NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p… Mitigation only Fix from $1,9502026-05-25 MEDIUM 5.5 CVE-2026-45246 Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users t… Summarize 0.15.1+ Fix from $1,6002026-05-18 MEDIUM 5.3 CVE-2026-8612 WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response f… Www\ 2.00+ Fix from $1,6002026-05-15 MEDIUM 6.5 CVE-2026-42937 Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These… Big Ip Access Policy Manager after 17.5.1.4 Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-41959 Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 7.9 CVE-2026-41217 A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or adm… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-40462 Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated att… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 HIGH 7.8 CVE-2026-8110 Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate th… Endpoint Manager after 2022 Fix from $1,9502026-05-12 HIGH 7.3 CVE-2026-0541 ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege esc… Axis Os 12.9.32+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-1185 A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escala… Axis Os 12.10.37+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-41489 Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and … Mitigation only Fix from $1,9502026-05-11 MEDIUM 6.1 CVE-2026-45222 Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions t… Patch available Fix from $1,6002026-05-11 HIGH 7.8 CVE-2026-8069 PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use… Nitrosense 3.00.3198 / 3.01.3056+ Fix from $1,9502026-05-08 HIGH 7.8 CVE-2026-41288 Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local use… Agent 1.25.03.0000+ Fix from $1,9502026-05-06 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 MEDIUM 5.5 CVE-2026-41366 OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary… Openclaw 2026.3.31+ Fix from $1,6002026-04-28 HIGH 7.1 CVE-2026-35341 A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a F… Coreutils No fix yet Fix from $1,9502026-04-22 MEDIUM 6.2 CVE-2026-6386 In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which… FreeBSD Mitigation only Fix from $1,6002026-04-22 MEDIUM 5.5 CVE-2026-6369 An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a… Livepatch Client 10.15.0+ Fix from $1,6002026-04-20 HIGH 7.8 CVE-2026-22676 Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by … Mitigation only Fix from $1,9502026-04-15 CRITICAL 9.1 CVE-2025-41118 Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (CO… Pyroscope 1.15.2+ Fix from $2,3002026-04-15 MEDIUM 6.8 CVE-2026-21011 Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock. Android Mitigation only Fix from $1,6002026-04-13 MEDIUM 5.5 CVE-2026-4482 The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read a… Insight Agent 4.1.0.2+ Fix from $1,6002026-04-10 MEDIUM 5.5 CVE-2026-28264 Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low p… Powerprotect Data Manager 20.1.0.0+ Fix from $1,6002026-04-08 MEDIUM 6.7 CVE-2026-33271 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902. True Image 2026+ Fix from $1,6002026-04-02