Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2020-12302
Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escala…
Driver \& Support Assistant
20.7.26.7+
HIGH 7.5
CVE-2020-26106
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
Cpanel
88.0.3+
HIGH 7.8
CVE-2020-17365
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially e…
Hotspot Shield
after 10.3.0
MEDIUM 6.0
CVE-2020-3503
A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access …
Ios Xe
Mitigation only
CRITICAL 9.8
CVE-2020-12842
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.
Ismartgate Pro Firmware
No fix yet
CRITICAL 9.8
CVE-2020-12838
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.
Ismartgate Pro Firmware
No fix yet
CRITICAL 9.8
CVE-2020-12839
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.
Ismartgate Pro Firmware
No fix yet
HIGH 7.8
CVE-2020-25826
PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.
Pingid Integration For Windows Login
2.4.2+
HIGH 7.8
CVE-2020-16202
WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution wi…
Webaccess
9.0.1+
HIGH 7.8
CVE-2020-11855
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow lo…
Operation Bridge Reporter
after 10.40
HIGH 8.8
CVE-2020-15776
An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as Http…
Enterprise
after 2020.2.4
MEDIUM 6.1
CVE-2014-10402
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed …
Dbi
after 1.643
MEDIUM 5.5
CVE-2020-10781
A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/cla…
Linux Kernel
5.8.0+
MEDIUM 6.1
CVE-2014-10401
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed v…
Dbi
1.632+
HIGH 7.8
CVE-2020-7314
Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior t…
Mcafee Agent
5.6.6+
HIGH 7.8
CVE-2020-23834
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by r…
Barracudadrive
No fix yet
HIGH 8.8
CVE-2020-5369
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authent…
Emc Isilon Onefs
Mitigation only
CRITICAL 9.8
CVE-2020-24355
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows …
Vmg5313 B30b Firmware
after 5.13
MEDIUM 6.5
CVE-2020-17402
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4 (47270). An attacke…
Parallels Desktop
16.0.0+
HIGH 8.8
CVE-2020-5417
Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is tr…
Capi Release
1.97.0 / 13.12.0+
HIGH 7.1
CVE-2020-24394
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks…
Linux Kernel
5.7.8+
HIGH 7.8
CVE-2020-5385
Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of…
Encryption
2.8 / 10.8+
HIGH 7.8
CVE-2020-0559
Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticat…
Ac 3165 Firmware
21.40.5.1+
HIGH 8.8
CVE-2020-8731
Incorrect execution-assigned permissions in the file system for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 m…
Server Board S2600wt Firmware
1.59+
HIGH 7.8
CVE-2020-6295
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat…
Adaptive Server Enterprise
Mitigation only
MEDIUM 5.5
CVE-2020-4631
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full cont…
Spectrum Protect Plus
after 10.1.6
HIGH 7.8
CVE-2019-19455
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamin…
Streaming Engine
4.8.5+
HIGH 7.5
CVE-2020-13915
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via a…
Unleashed Firmware
after 200.7.10.102.92
MEDIUM 5.0
CVE-2014-1422
In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the applic…
Trust Store \(ubuntu\)
1.1.0+
CRITICAL 9.8
CVE-2020-9671
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead…
Creative Cloud Desktop Application
after 5.1