İçeriğe atla
Noroxi

CWE-732 · 1.473 kayıt

Incorrect Permission Assignment for Critical Resource

Bu sınıftaki CVE’ler

1.476 kayıt

  • CVE-2019-15752
    76Bu hafta

    Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.ex

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %49

    docker · docker28 Ağu 2019

  • CVE-2022-22960
    72Bu hafta

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissio

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %36

    vmware · cloud foundation13 Nis 2022

  • CVE-2011-3923
    66Bu hafta

    Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary

    KritikCVSS 9,8SilahlaştırılmışEPSS %89

    apache · struts1 Kas 2019

  • CVE-2018-13374
    58Planlayın

    A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obt

    OrtaCVSS 4,3KEVSilahlaştırılmışEPSS %38

    fortinet · fortiadc22 Oca 2019

  • CVE-2023-32986
    53Planlayın

    Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File

    YüksekCVSS 8,8İstismar yokEPSS %61

    jenkins · file parameters16 May 2023

  • CVE-2017-16885
    49Planlayın

    Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Us

    KritikCVSS 9,8Kavram kanıtıEPSS %33

    fiberhome · lm53q1 firmware12 Oca 2018

  • CVE-2018-1000207
    47Planlayın

    MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt

    YüksekCVSS 7,2İstismar yokEPSS %64

    modx · modx revolution13 Tem 2018

  • CVE-2018-4072
    43Planlayın

    An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink

    YüksekCVSS 8,8İstismar yokEPSS %26

    sierrawireless · airlink es450 firmware6 May 2019

  • CVE-2018-4073
    43Planlayın

    An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink

    YüksekCVSS 8,8İstismar yokEPSS %26

    sierrawireless · airlink es450 firmware6 May 2019

  • CVE-2018-10285
    43Planlayın

    The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.

    KritikCVSS 9,8Kavram kanıtıEPSS %13

    ericssonlg · ipecs nms22 Nis 2018

  • CVE-2018-1000226
    43Planlayın

    Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older version

    KritikCVSS 9,8Kavram kanıtıEPSS %13

    cobblerd · cobbler20 Ağu 2018

  • CVE-2020-11107
    42Planlayın

    An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.

    YüksekCVSS 8,8Kavram kanıtıEPSS %22

    apachefriends · xampp2 Nis 2020

  • CVE-2022-43773
    42Planlayın

    Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource

    YüksekCVSS 8,8İstismar yokEPSS %22

    hitachi · vantara pentaho business analytics server3 Nis 2023

  • CVE-2017-9462
    42Planlayın

    In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbi

    YüksekCVSS 8,8SilahlaştırılmışEPSS %22

    mercurial · mercurial6 Haz 2017

  • CVE-2026-21902
    42Planlayın

    Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root

    KritikCVSS 9,3Kavram kanıtıEPSS %18

    juniper · junos os evolved25 Şub 2026

  • CVE-2018-14916
    41Planlayın

    LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

    KritikCVSS 9,1Kavram kanıtıEPSS %17

    loytec · lgate-902 firmware28 Haz 2019

  • CVE-2017-8857
    41Planlayın

    In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote comman

    KritikCVSS 9,8İstismar yokEPSS %6

    veritas · netbackup9 May 2017

  • CVE-2019-7958
    40Planlayın

    Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %4

    adobe · creative cloud16 Ağu 2019

  • CVE-2017-9602
    40Planlayın

    KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    kbvault mysql project · kbvault mysql16 Haz 2017

  • CVE-2019-8256
    40Planlayın

    ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %4

    adobe · coldfusion19 Ara 2019

  • CVE-2020-9671
    40Planlayın

    Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %4

    adobe · creative cloud desktop application16 Tem 2020

  • CVE-2020-28910
    40Planlayın

    Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of s

    KritikCVSS 9,8İstismar yokEPSS %4

    nagios · nagios xi24 May 2021

  • CVE-2018-10381
    40Planlayın

    TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.

    KritikCVSS 9,8İstismar yokEPSS %4

    mcafee · tunnelbear25 Nis 2018

  • CVE-2017-8856
    40Planlayın

    In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution u

    KritikCVSS 9,8İstismar yokEPSS %4

    veritas · netbackup9 May 2017

  • CVE-2017-6950
    40Planlayın

    SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABA

    KritikCVSS 9,8İstismar yokEPSS %4

    sap · gui for windows23 Mar 2017

Tüm zafiyet sınıfları