Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 6.0 CVE-2025-12147 In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclu… Mitigation only Fix from $1,6002025-10-29 MEDIUM 6.0 CVE-2025-12148 In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of… Mitigation only Fix from $1,6002025-10-29 HIGH 7.1 CVE-2025-62688 An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab… Mitigation only Fix from $1,9502025-10-23 CRITICAL 10.0 CVE-2025-12004 Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse… Mitigation only Fix from $2,3002025-10-21 MEDIUM 6.8 CVE-2025-31702 A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vul… Mitigation only Fix from $1,6002025-10-15 HIGH 7.8 CVE-2025-57741 An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all… Forticlient 7.2.12 / 7.4.4+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-62251 Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA… Digital Experience Platform 7.4.3.119 / 2023.q3.9+ Fix from $1,6002025-10-13 MEDIUM 6.7 CVE-2025-8886 Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A… Mitigation only Fix from $1,6002025-10-10 HIGH 7.8 CVE-2025-10751 MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects MacForge: 1.2… Macforge No fix yet Fix from $1,9502025-10-04 CRITICAL 9.8 CVE-2025-34212 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments… Virtual Appliance Application 20.0.1923 / 22.0.843+ Fix from $2,3002025-09-29 HIGH 7.8 CVE-2025-10541 iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure upda… Mitigation only Fix from $1,9502025-09-25 MEDIUM 5.3 CVE-2025-43808 The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA t… Digital Experience Platform 7.4.3.113 / 2023.Q4.9+ Fix from $1,6002025-09-19 CRITICAL 9.8 CVE-2025-34206 Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configuration and secret material un… Virtual Appliance Application Mitigation only Fix from $2,3002025-09-19 HIGH 7.8 CVE-2025-34189 Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client… Virtual Appliance Application 1.0.735 / 20.0.1330+ Fix from $1,9502025-09-19 HIGH 8.1 CVE-2025-54497 Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgr… Mitigation only Fix from $1,9502025-09-18 HIGH 8.1 CVE-2025-52873 Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgr… Mitigation only Fix from $1,9502025-09-18 CRITICAL 9.1 CVE-2025-10643 Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authen… Repairit Mitigation only Fix from $2,3002025-09-17 HIGH 7.8 CVE-2025-57392 BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone and BUILTIN\Users groups FIL… Benimpos No fix yet Fix from $1,9502025-09-10 CRITICAL 9.1 CVE-2025-40804 A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share … Mitigation only Fix from $2,3002025-09-09 HIGH 7.5 CVE-2025-41664 A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission … Mitigation only Fix from $1,9502025-09-08 CRITICAL 9.8 CVE-2025-58372 Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS C… Roo Code 3.26.0+ Fix from $2,3002025-09-05 MEDIUM 6.5 CVE-2025-10059 An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is … MongoDB 6.0.24 / 7.0.18+ Fix from $1,6002025-09-05 HIGH 7.3 CVE-2025-23258 NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker with low privileges to escalate … No fix yet Fix from $1,9502025-09-04 HIGH 7.3 CVE-2025-23257 NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privileges to escalate privileges. A… No fix yet Fix from $1,9502025-09-04 MEDIUM 6.7 CVE-2025-36193 IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation in… Transformation Advisor 4.3.2+ Fix from $1,6002025-09-03 HIGH 7.8 CVE-2025-43268 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root p… macOS 15.6+ Fix from $1,9502025-08-29 HIGH 7.8 CVE-2025-9578 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor… Mitigation only Fix from $1,9502025-08-28 HIGH 7.0 CVE-2025-53396 Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier), which may al… Mitigation only Fix from $1,9502025-08-28 HIGH 7.8 CVE-2025-43729 Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A local low-privileg… Thinos 2508+ Fix from $1,9502025-08-27 CRITICAL 9.4 CVE-2025-30063 The configuration file containing database logins and passwords is readable by any local user. Mitigation only Fix from $2,3002025-08-27