Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2019-7958
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exploitation could lea…
Creative Cloud
after 4.6.1
MEDIUM 5.5
CVE-2019-15119
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a …
Nps
after 0.23.2
HIGH 7.8
CVE-2019-15084
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate…
Waves Maxx Audio
No fix yet
MEDIUM 6.5
CVE-2018-12357
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
Cloudvision Portal
after 2018.1.1
HIGH 8.8
CVE-2019-0341
The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the a…
Enable Now
Mitigation only
HIGH 7.8
CVE-2019-12808
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can over…
Altools
after 18.1
HIGH 7.8
CVE-2019-14969
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service …
Auditor
9.8+
HIGH 7.8
CVE-2019-14935
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control a…
3cx
No fix yet
HIGH 7.3
CVE-2019-1944
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to…
Adaptive Security Appliance Software
9.4.4.37+
MEDIUM 6.6
CVE-2019-14743
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which al…
Steam Client
after 2019-08-07
HIGH 7.5
CVE-2019-11270
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can by…
Application Service
2.3.15 / 2.3.22+
MEDIUM 5.4
CVE-2018-20905
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).
Cpanel
62.0.47 / 68.0.39+
MEDIUM 5.5
CVE-2018-20908
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).
Cpanel
62.0.47 / 68.0.39+
HIGH 7.1
CVE-2018-20909
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).
Cpanel
62.0.42 / 68.0.33+
CRITICAL 9.8
CVE-2018-20871
In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) oc…
Grid Engine
Mitigation only
HIGH 8.1
CVE-2018-2024
IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unint…
Qradar Security Information And Event Manager
Patch available
CRITICAL 9.8
CVE-2019-1010101
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The…
Rufus
after 3.0
MEDIUM 5.5
CVE-2019-5222
There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R…
Honor Magic 2 Firmware
Mitigation only
HIGH 7.3
CVE-2019-12876
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio…
Manageengine Admanager Plus
No fix yet
CRITICAL 9.8
CVE-2019-1010009
DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT …
Dglux Server
Mitigation only
HIGH 7.8
CVE-2019-12577
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run …
Private Internet Access Vpn Client
No fix yet
MEDIUM 5.5
CVE-2019-13142
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located …
Surround
Mitigation only
HIGH 7.3
CVE-2019-13208
WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to …
Waves Maxx Audio
No fix yet
MEDIUM 6.5
CVE-2018-14861
Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of …
Odoo
Patch available
MEDIUM 6.5
CVE-2018-14862
Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated i…
Odoo
Patch available
CRITICAL 9.1
CVE-2018-14916EPSS 17%
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
Lgate 902 Firmware
6.4.2+
HIGH 7.5
CVE-2019-13012
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL,…
Glib
2.59.1+
HIGH 7.8
CVE-2019-2023
In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could al…
Android
Mitigation only
HIGH 7.8
CVE-2019-12133
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…
Manageengine Analytics Plus
Mitigation only
HIGH 7.8
CVE-2018-19446
A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataOb…
Foxit Pdf Sdk Activex
after 5.5.0