Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2025-0093
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to re…
Android
Mitigation only
CRITICAL 9.6
CVE-2025-4609
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to poten…
Chrome
136.0.7103.113+
HIGH 7.8
CVE-2025-52094
Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via the \HKLM\SYSTEM\Setup\SmartD…
Smart Deploy
3.0.2046+
MEDIUM 5.3
CVE-2025-38742
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low pr…
Emc Idrac Service Module
6.0.3.0+
HIGH 7.3
CVE-2025-55524
Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
Agent Zero
0.9.0+
HIGH 8.8
CVE-2025-27216
Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate p…
Mitigation only
CRITICAL 9.8
CVE-2025-8042
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 14…
Firefox
141.0+
MEDIUM 5.0
CVE-2025-5819
An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could ha…
GitLab
17.11.6 / 18.0.4+
HIGH 7.8
CVE-2025-50675
GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory i…
Mitigation only
MEDIUM 5.7
CVE-2025-54618
Permission control vulnerability in the distributed clipboard module.
Impact: Successful exploitation of this vulnerability may affect service confid…
Harmonyos
No fix yet
CRITICAL 9.8
CVE-2012-10030
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive syste…
Freefloat Ftp Server
Mitigation only
HIGH 8.8
CVE-2025-46093
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by l…
Liquidfiles
4.1.2+
HIGH 8.3
CVE-2025-41659
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys.…
Mitigation only
MEDIUM 5.5
CVE-2025-23285
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of…
Mitigation only
CRITICAL 9.8
CVE-2025-45150
Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafte…
Langchain Chatglm Webui
Mitigation only
CRITICAL 10.0
CVE-2014-125121
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combin…
Mitigation only
MEDIUM 5.1
CVE-2025-43266
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…
macOS
13.7.7 / 14.7.7+
CRITICAL 9.8
CVE-2025-43243
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…
macOS
13.7.7 / 14.7.7+
MEDIUM 5.5
CVE-2025-43247
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…
macOS
13.7.7 / 14.7.7+
CRITICAL 9.8
CVE-2025-26469
An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840.
A …
Pacs Server
Mitigation only
CRITICAL 9.3
CVE-2017-20198
The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount conf…
No fix yet
MEDIUM 6.5
CVE-2025-36104
IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions in…
Storage Scale
Mitigation only
MEDIUM 6.8
CVE-2023-39338
Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry polic…
Mitigation only
HIGH 7.3
CVE-2025-30661
An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, lo…
Junos
Mitigation only
HIGH 7.8
CVE-2025-27446
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner).
Local listening file permissions in APISIX…
Apisix
after 0.5
HIGH 8.2
CVE-2025-6297
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i…
Dpkg
1.22.21+
MEDIUM 5.3
CVE-2024-11584
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it…
Cloud Init
25.1.3+
HIGH 7.0
CVE-2025-36537
Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on…
Mitigation only
CRITICAL 9.9
CVE-2025-49131
FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The …
Fastgpt
4.9.11+
HIGH 7.3
CVE-2025-48961
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 3…
Mitigation only