Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.8 CVE-2019-25245 Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improp… No fix yet Fix from $1,9502025-12-24 HIGH 7.8 CVE-2025-13703 VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala… Mitigation only Fix from $1,9502025-12-23 HIGH 8.4 CVE-2022-50690 Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to incorrect file permissions on executable files. Unprivileg… No fix yet Fix from $1,9502025-12-22 HIGH 8.4 CVE-2023-53949 AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent se… No fix yet Fix from $1,9502025-12-19 HIGH 8.8 CVE-2025-13941 A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system pe… Pdf Editor after 2025.2.1.33197 Fix from $1,9502025-12-19 MEDIUM 6.1 CVE-2025-67794 An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are … Drivelock 24.2.8 / 25.1.6+ Fix from $1,6002025-12-17 HIGH 7.8 CVE-2024-46060 Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. Duri… Anaconda3 2024.06-1+ Fix from $1,9502025-12-17 HIGH 7.8 CVE-2024-46062 Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. Dur… Miniconda3 23.11.0-1+ Fix from $1,9502025-12-17 MEDIUM 6.7 CVE-2025-34288 Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and applicati… Nagios Xi after 2024 Fix from $1,6002025-12-16 MEDIUM 5.5 CVE-2025-43470 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. A standard user may be able to view files ma… macOS 26.1+ Fix from $1,6002025-12-12 HIGH 7.8 CVE-2025-13733 BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issu… Buhontfs No fix yet Fix from $1,9502025-12-12 MEDIUM 6.5 CVE-2025-20386 In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can resu… Splunk 9.2.10 / 9.3.8+ Fix from $1,6002025-12-03 MEDIUM 6.5 CVE-2025-20387 In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version… Splunk 9.2.10 / 9.3.8+ Fix from $1,6002025-12-03 HIGH 8.8 CVE-2025-62575 NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by defa… Biodose\/nmis 23.0+ Fix from $1,9502025-12-02 HIGH 7.5 CVE-2025-64298 NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are exposed in the Windows share access… Biodose\/nmis 23.0+ Fix from $1,9502025-12-02 HIGH 7.8 CVE-2025-64642 NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenar… Biodose\/nmis 23.0+ Fix from $1,9502025-12-02 HIGH 8.5 CVE-2025-59373 A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivi… Mitigation only Fix from $1,9502025-11-25 HIGH 8.5 CVE-2025-11921 iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue a… Mitigation only Fix from $1,9502025-11-24 HIGH 7.7 CVE-2025-64324 KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by … Kubevirt 1.6.1+ Fix from $1,9502025-11-18 HIGH 7.8 CVE-2025-34323 Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-w… Log Server 2026+ Fix from $1,9502025-11-17 HIGH 7.8 CVE-2024-32010 A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of… Mitigation only Fix from $1,9502025-11-11 MEDIUM 6.7 CVE-2025-8108 An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerabil… Axis Os 12.7.33+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-6779 An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerabi… Axis Os 12.6.40+ Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-64319 Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Config… Mulesoft Anypoint Code Builder 1.12.1+ Fix from $1,6002025-11-04 MEDIUM 5.3 CVE-2025-64322 Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configurat… Agentforce Vibes 3.3.0+ Fix from $1,6002025-11-04 MEDIUM 6.8 CVE-2025-4952 Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to un… Mitigation only Fix from $1,6002025-10-31 HIGH 7.8 CVE-2025-34287 Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but own… Nagios Xi 2024+ Fix from $1,9502025-10-30 MEDIUM 6.7 CVE-2025-11906 A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect file permissions, allowing a… Mitigation only Fix from $1,6002025-10-30 HIGH 7.8 CVE-2025-54545 On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges. Mitigation only Fix from $1,9502025-10-29 HIGH 7.5 CVE-2025-54546 On affected platforms, restricted users could use SSH port forwarding to access host-internal services Mitigation only Fix from $1,9502025-10-29