Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-17873
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacke…
Wifiranger Firmware
after 7.0.8
HIGH 7.0
CVE-2017-18348
Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by …
Splunk
after 6.6.11
HIGH 7.8
CVE-2018-11080
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple c…
Secure Remote Services
3.32.00.08+
HIGH 7.8
CVE-2018-13399
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak…
Crucible
4.6.1+
HIGH 8.8
CVE-2018-17892
NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to no…
Nuuo Cms
after 3.1
MEDIUM 5.3
CVE-2018-1724
IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permissio…
Spectrum Lsf
Patch available
HIGH 7.6
CVE-2018-12173
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may…
Server Board S2600bp Firmware
00.01.0014+
HIGH 7.8
CVE-2018-12131
Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083 may allow an authenticate…
Client Nvme
4.0.0.1007 / 4.7.0.2083+
HIGH 7.8
CVE-2018-8411
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind…
Windows 10
Patch available
HIGH 7.8
CVE-2018-17775
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by rep…
End Point Security
No fix yet
HIGH 8.1
CVE-2018-1750
IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifi…
Security Key Lifecycle Manager
after 2.7.0.4
HIGH 7.8
CVE-2018-11064
Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A l…
Emc Unity Operating Environment
after 4.3.1.1525703027
CRITICAL 9.8
CVE-2018-15379EPSS 86%
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticate…
Prime Infrastructure
No fix yet
HIGH 7.3
CVE-2018-0422
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally s…
Webex Meetings Online
1.3.37 / 32.15.20+
HIGH 8.8
CVE-2018-17872
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.
Collaboration Compliance
9.2.1.5545+
HIGH 7.0
CVE-2018-6261
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which sets incorrect permissions on a file, which may to …
Geforce Experience
3.15+
MEDIUM 6.5
CVE-2018-1420
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) in…
Websphere Portal
Patch available
HIGH 7.8
CVE-2018-17776
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replaci…
Antivirus
No fix yet
MEDIUM 5.0
CVE-2018-14650
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada…
Enterprise Linux Desktop
Patch available
HIGH 7.8
CVE-2018-14327
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak pe…
Ee40vb Firmware
Patch available
HIGH 7.8
CVE-2018-16588
Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux E…
Shadow
after 4.5-5.39
HIGH 7.5
CVE-2018-8848
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exp…
E Alert Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-6040
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security pol…
Chrome
64.0.3282.119+
MEDIUM 5.8
CVE-2018-14825
On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN…
Cn80
Mitigation only
CRITICAL 9.8
CVE-2018-11240
An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol…
T Router Firmware
Mitigation only
HIGH 7.8
CVE-2018-1711
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to all…
Db2
Mitigation only
HIGH 7.8
CVE-2018-11277
In Snapdragon (Automobile, Mobile, Wear) in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 6…
Msm8909w Firmware
Mitigation only
MEDIUM 5.4
CVE-2018-16958
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, when Internet Information Servic…
Webcenter Interaction
Mitigation only
HIGH 8.8
CVE-2018-17037
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
Ucms
No fix yet
HIGH 7.8
CVE-2018-12162
Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code…
Openvino Toolkit
2018.1.265+