Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 5.5 CVE-2026-26100 Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request. Opds Talon Mitigation only Fix from $1,6002026-02-20 HIGH 7.8 CVE-2026-26101 Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request. Opds Talon Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-24834 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. I… Kata Containers 3.27.0+ Fix from $1,9502026-02-19 MEDIUM 5.5 CVE-2026-1344 Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal. Enforce Recovery Key Portal 1.62.5+ Fix from $1,6002026-02-18 HIGH 7.4 CVE-2025-33088 IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to … Concert 2.2.0+ Fix from $1,9502026-02-17 HIGH 7.8 CVE-2026-23648 Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several… Mitigation only Fix from $1,9502026-02-17 HIGH 7.8 CVE-2019-25344 Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application … Mobilego No fix yet Fix from $1,9502026-02-12 HIGH 7.8 CVE-2019-25343 NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attacker… No fix yet Fix from $1,9502026-02-12 HIGH 7.0 CVE-2025-61969 Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arb… Mitigation only Fix from $1,9502026-02-11 MEDIUM 6.7 CVE-2025-35999 Incorrect permission assignment for critical resource for some System Firmware Update Utility (SysFwUpdt) for Intel(R) Server Boards and Intel(R) Ser… Mitigation only Fix from $1,6002026-02-10 MEDIUM 6.7 CVE-2025-14740 Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\Docker… Mitigation only Fix from $1,6002026-02-04 HIGH 7.5 CVE-2025-52627 Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially … Aion Mitigation only Fix from $1,9502026-02-03 CRITICAL 10.0 CVE-2025-14988 A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the… No fix yet Fix from $2,3002026-01-27 HIGH 8.8 CVE-2020-36938 WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables. Attack… No fix yet Fix from $1,9502026-01-27 MEDIUM 5.5 CVE-2026-24131 pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validatin… Pnpm 10.28.2+ Fix from $1,6002026-01-26 HIGH 7.0 CVE-2026-0775 npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on… Mitigation only Fix from $1,9502026-01-23 MEDIUM 5.5 CVE-2026-22280 Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from… Powerscale Onefs 9.5.1.6 / 9.7.1.11+ Fix from $1,6002026-01-22 MEDIUM 5.5 CVE-2026-24049 wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vu… Wheel 0.46.2+ Fix from $1,6002026-01-22 MEDIUM 6.0 CVE-2026-20092 A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administra… Mitigation only Fix from $1,6002026-01-21 HIGH 8.4 CVE-2025-12985 IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running… Mitigation only Fix from $1,9502026-01-20 HIGH 8.4 CVE-2021-47756 Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root priv… No fix yet Fix from $1,9502026-01-16 MEDIUM 5.5 CVE-2025-59961 An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS … Junos 21.2 / 22.4+ Fix from $1,6002026-01-15 HIGH 7.3 CVE-2025-67246 A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This dr… Ludashi Driver 5.1025+ Fix from $1,9502026-01-15 HIGH 7.8 CVE-2022-50931 TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. … Teamspeak No fix yet Fix from $1,9502026-01-13 CRITICAL 10.0 CVE-2025-69426 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an … Mitigation only Fix from $2,3002026-01-09 HIGH 7.8 CVE-2025-14979 AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects … Eddie No fix yet Fix from $1,9502026-01-06 HIGH 8.8 CVE-2020-36916 TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. A… No fix yet Fix from $1,9502026-01-06 HIGH 8.8 CVE-2021-47742 Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users to modify executable files wit… No fix yet Fix from $1,9502025-12-31 HIGH 7.8 CVE-2025-64699 An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, app… Ec2007 Kernel No fix yet Fix from $1,9502025-12-31 HIGH 7.5 CVE-2025-66723 inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to … Engine Dj Desktop 4.3.4+ Fix from $1,9502025-12-30