CWE-732 · 1.473 kayıt
Incorrect Permission Assignment for Critical Resource
Bu sınıftaki CVE’ler
1.476 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
76Bu hafta | CVE-2019-15752Silahlaştırılmış | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exdocker · docker · CWE-732 | Yüksek7,8 | KEV | %48,6 | 28 Ağu 2019 |
72Bu hafta | CVE-2022-22960Silahlaştırılmış | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissiovmware · cloud foundation · CWE-732 | Yüksek7,8 | KEV | %35,5 | 13 Nis 2022 |
66Bu hafta | CVE-2011-3923Silahlaştırılmış | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary apache · struts · CWE-732 | Kritik9,8 | — | %89,5 | 1 Kas 2019 |
58Planlayın | CVE-2018-13374Silahlaştırılmış | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtfortinet · fortiadc · CWE-732 | Orta4,3 | KEV | %37,8 | 22 Oca 2019 |
53Planlayın | CVE-2023-32986İstismar yok | Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File jenkins · file parameters · CWE-732 | Yüksek8,8 | — | %60,7 | 16 May 2023 |
49Planlayın | CVE-2017-16885Kavram kanıtı | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usfiberhome · lm53q1 firmware · CWE-732 | Kritik9,8 | — | %33,5 | 12 Oca 2018 |
47Planlayın | CVE-2018-1000207İstismar yok | MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phptmodx · modx revolution · CWE-732 | Yüksek7,2 | — | %64,1 | 13 Tem 2018 |
43Planlayın | CVE-2018-4072İstismar yok | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLinksierrawireless · airlink es450 firmware · CWE-732 | Yüksek8,8 | — | %26,4 | 6 May 2019 |
43Planlayın | CVE-2018-4073İstismar yok | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLinksierrawireless · airlink es450 firmware · CWE-732 | Yüksek8,8 | — | %25,6 | 6 May 2019 |
43Planlayın | CVE-2018-10285Kavram kanıtı | The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.ericssonlg · ipecs nms · CWE-732 | Kritik9,8 | — | %12,8 | 22 Nis 2018 |
43Planlayın | CVE-2018-1000226Kavram kanıtı | Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versioncobblerd · cobbler · CWE-732 | Kritik9,8 | — | %12,6 | 20 Ağu 2018 |
42Planlayın | CVE-2020-11107Kavram kanıtı | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.apachefriends · xampp · CWE-732 | Yüksek8,8 | — | %22,5 | 2 Nis 2020 |
42Planlayın | CVE-2022-43773İstismar yok | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resourcehitachi · vantara pentaho business analytics server · CWE-732 | Yüksek8,8 | — | %22,2 | 3 Nis 2023 |
42Planlayın | CVE-2017-9462Silahlaştırılmış | In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbimercurial · mercurial · CWE-732 | Yüksek8,8 | — | %21,7 | 6 Haz 2017 |
42Planlayın | CVE-2026-21902Kavram kanıtı | Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as rootjuniper · junos os evolved · CWE-732 | Kritik9,3 | — | %18,0 | 25 Şub 2026 |
41Planlayın | CVE-2018-14916Kavram kanıtı | LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.loytec · lgate-902 firmware · CWE-732 | Kritik9,1 | — | %17,2 | 28 Haz 2019 |
41Planlayın | CVE-2017-8857İstismar yok | In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote commanveritas · netbackup · CWE-732 | Kritik9,8 | — | %5,7 | 9 May 2017 |
40Planlayın | CVE-2019-7958İstismar yok | Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.adobe · creative cloud · CWE-732 | Kritik9,8 | — | %4,4 | 16 Ağu 2019 |
40Planlayın | CVE-2017-9602Kavram kanıtı | KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.kbvault mysql project · kbvault mysql · CWE-732 | Kritik9,8 | — | %4,3 | 16 Haz 2017 |
40Planlayın | CVE-2019-8256İstismar yok | ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.adobe · coldfusion · CWE-732 | Kritik9,8 | — | %4,0 | 19 Ara 2019 |
40Planlayın | CVE-2020-9671İstismar yok | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.adobe · creative cloud desktop application · CWE-732 | Kritik9,8 | — | %4,0 | 16 Tem 2020 |
40Planlayın | CVE-2020-28910İstismar yok | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of snagios · nagios xi · CWE-732 | Kritik9,8 | — | %3,9 | 24 May 2021 |
40Planlayın | CVE-2018-10381İstismar yok | TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.mcafee · tunnelbear · CWE-732 | Kritik9,8 | — | %3,8 | 25 Nis 2018 |
40Planlayın | CVE-2017-8856İstismar yok | In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution uveritas · netbackup · CWE-732 | Kritik9,8 | — | %3,8 | 9 May 2017 |
40Planlayın | CVE-2017-6950İstismar yok | SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAsap · gui for windows · CWE-732 | Kritik9,8 | — | %3,8 | 23 Mar 2017 |
- CVE-2019-1575276Bu hafta
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.ex
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %49docker · docker28 Ağu 2019
- CVE-2022-2296072Bu hafta
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissio
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %36vmware · cloud foundation13 Nis 2022
- CVE-2011-392366Bu hafta
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary
KritikCVSS 9,8SilahlaştırılmışEPSS %89apache · struts1 Kas 2019
- CVE-2018-1337458Planlayın
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obt
OrtaCVSS 4,3KEVSilahlaştırılmışEPSS %38fortinet · fortiadc22 Oca 2019
- CVE-2023-3298653Planlayın
Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File
YüksekCVSS 8,8İstismar yokEPSS %61jenkins · file parameters16 May 2023
- CVE-2017-1688549Planlayın
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Us
KritikCVSS 9,8Kavram kanıtıEPSS %33fiberhome · lm53q1 firmware12 Oca 2018
- CVE-2018-100020747Planlayın
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt
YüksekCVSS 7,2İstismar yokEPSS %64modx · modx revolution13 Tem 2018
- CVE-2018-407243Planlayın
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink
YüksekCVSS 8,8İstismar yokEPSS %26sierrawireless · airlink es450 firmware6 May 2019
- CVE-2018-407343Planlayın
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink
YüksekCVSS 8,8İstismar yokEPSS %26sierrawireless · airlink es450 firmware6 May 2019
- CVE-2018-1028543Planlayın
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.
KritikCVSS 9,8Kavram kanıtıEPSS %13ericssonlg · ipecs nms22 Nis 2018
- CVE-2018-100022643Planlayın
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older version
KritikCVSS 9,8Kavram kanıtıEPSS %13cobblerd · cobbler20 Ağu 2018
- CVE-2020-1110742Planlayın
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.
YüksekCVSS 8,8Kavram kanıtıEPSS %22apachefriends · xampp2 Nis 2020
- CVE-2022-4377342Planlayın
Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource
YüksekCVSS 8,8İstismar yokEPSS %22hitachi · vantara pentaho business analytics server3 Nis 2023
- CVE-2017-946242Planlayın
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbi
YüksekCVSS 8,8SilahlaştırılmışEPSS %22mercurial · mercurial6 Haz 2017
- CVE-2026-2190242Planlayın
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
KritikCVSS 9,3Kavram kanıtıEPSS %18juniper · junos os evolved25 Şub 2026
- CVE-2018-1491641Planlayın
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
KritikCVSS 9,1Kavram kanıtıEPSS %17loytec · lgate-902 firmware28 Haz 2019
- CVE-2017-885741Planlayın
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote comman
KritikCVSS 9,8İstismar yokEPSS %6veritas · netbackup9 May 2017
- CVE-2019-795840Planlayın
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4adobe · creative cloud16 Ağu 2019
- CVE-2017-960240Planlayın
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.
KritikCVSS 9,8Kavram kanıtıEPSS %4kbvault mysql project · kbvault mysql16 Haz 2017
- CVE-2019-825640Planlayın
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4adobe · coldfusion19 Ara 2019
- CVE-2020-967140Planlayın
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4adobe · creative cloud desktop application16 Tem 2020
- CVE-2020-2891040Planlayın
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of s
KritikCVSS 9,8İstismar yokEPSS %4nagios · nagios xi24 May 2021
- CVE-2018-1038140Planlayın
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.
KritikCVSS 9,8İstismar yokEPSS %4mcafee · tunnelbear25 Nis 2018
- CVE-2017-885640Planlayın
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution u
KritikCVSS 9,8İstismar yokEPSS %4veritas · netbackup9 May 2017
- CVE-2017-695040Planlayın
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABA
KritikCVSS 9,8İstismar yokEPSS %4sap · gui for windows23 Mar 2017