Vulnerability index

Browse CVEs

1,498 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 5.5 CVE-2024-45655 IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignme… Application Gateway after 24.09 Fix from $1,6002025-06-03 HIGH 8.0 CVE-2025-20298 In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can resu… Universal Forwarder 9.1.9 / 9.2.6+ Fix from $1,9502025-06-02 HIGH 7.1 CVE-2025-2503 An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions… Pcmanager 5.1.110.5082+ Fix from $1,9502025-05-30 MEDIUM 5.0 CVE-2025-48747 Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment fo… Directory Manager 11.1.25134.03+ Fix from $1,6002025-05-28 MEDIUM 5.5 CVE-2025-48382 Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates… Fess 14.19.2+ Fix from $1,6002025-05-27 MEDIUM 6.0 CVE-2025-46802 For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session. Mitigation only Fix from $1,6002025-05-26 HIGH 8.5 CVE-2025-40672 A Privilege Escalation vulnerability has been found in Panloader component v3.24.0.0 by Espiral MS Group. This vulnerability allows any user to overr… Mitigation only Fix from $1,9502025-05-26 HIGH 8.8 CVE-2025-45472 Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account. Autodeploy Layer after 1.2.0 Fix from $1,9502025-05-22 HIGH 8.8 CVE-2025-45468 Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account. Fc Stable Diffusion after 1.0.18 Fix from $1,9502025-05-22 HIGH 8.8 CVE-2025-45471 Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account. Measure Cold Start after 1.4.1 Fix from $1,9502025-05-22 MEDIUM 5.5 CVE-2025-32915 Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42… Checkmk Mitigation only Fix from $1,6002025-05-22 CRITICAL 9.8 CVE-2025-3944 Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX a… Niagara Mitigation only Fix from $2,3002025-05-22 CRITICAL 9.8 CVE-2025-3936 Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on W… Niagara Mitigation only Fix from $2,3002025-05-22 HIGH 7.8 CVE-2025-2759 GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges … Gstreamer 1.25.1+ Fix from $1,9502025-05-22 HIGH 8.6 CVE-2025-34025 The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe defaul… Mitigation only Fix from $1,9502025-05-21 MEDIUM 5.5 CVE-2025-31262 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visio… Ipados 2.3 / 11.3+ Fix from $1,6002025-05-19 MEDIUM 5.5 CVE-2025-40572 A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permi… Scalance Lpe9403 Firmware Mitigation only Fix from $1,6002025-05-13 HIGH 7.8 CVE-2025-40574 A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permi… Scalance Lpe9403 Firmware Mitigation only Fix from $1,9502025-05-13 MEDIUM 5.9 CVE-2025-24009 A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected… Mitigation only Fix from $1,6002025-05-13 MEDIUM 6.6 CVE-2025-42997 Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due … Mitigation only Fix from $1,6002025-05-13 HIGH 8.1 CVE-2025-26168 IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file t… Mitigation only Fix from $1,9502025-05-07 HIGH 8.1 CVE-2025-26169 IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that ca… Mitigation only Fix from $1,9502025-05-07 MEDIUM 5.5 CVE-2025-23245 NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to access globa… No fix yet Fix from $1,6002025-05-01 MEDIUM 5.5 CVE-2025-3395 Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue … Automation Builder after 2.8.0 Fix from $1,6002025-04-30 HIGH 7.8 CVE-2025-3394 Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0. Automation Builder after 2.8.0 Fix from $1,9502025-04-30 MEDIUM 6.7 CVE-2025-30408 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) befor… Mitigation only Fix from $1,6002025-04-24 HIGH 7.3 CVE-2025-0926 Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a… Camera Station Pro 6.8.43213+ Fix from $1,9502025-04-23 HIGH 7.8 CVE-2025-1731 An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V… Uos 1.32+ Fix from $1,9502025-04-22 MEDIUM 6.1 CVE-2025-0758 Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintend… Mitigation only Fix from $1,6002025-04-16 HIGH 7.5 CVE-2025-30708 Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions that are a… User Management after 12.2.14 Fix from $1,9502025-04-15